CVE-2004-0819: Medium severity OpenBSD OpenBSD vulnerability
Published Aug 25, 2004
·Updated
The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service (crash) via an ICMP echo (ping) packet.
Affected Software
4 affected components
OpenBSD OpenBSD=3.3
OpenBSD OpenBSD=3.2
OpenBSD OpenBSD=3.5
OpenBSD OpenBSD=3.4
Remediation
Patch Available
Event History
Aug 25, 2004
CVE Published
04:00 AM
Sep 2, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0819?
CVE-2004-0819 has a medium severity rating as it can lead to a denial of service.
2
Which versions of OpenBSD are affected by CVE-2004-0819?
CVE-2004-0819 affects OpenBSD versions 3.2, 3.3, 3.4, and 3.5.
3
How do I fix CVE-2004-0819?
To fix CVE-2004-0819, upgrade your OpenBSD to a version that is not vulnerable, such as 3.6 or later.
4
What type of attack does CVE-2004-0819 allow?
CVE-2004-0819 allows remote attackers to perform denial of service attacks using ICMP echo (ping) packets.
5
Is there a workaround for CVE-2004-0819?
A workaround for CVE-2004-0819 is to disable the bridging firewall functionality with the link2 option for IPSec.