CVE-2004-2230: Buffer Overflow
Published Dec 31, 2004
·Updated
Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.
Affected Software
3 affected components
OpenBSD OpenBSD=3.6
OpenBSD OpenBSD=3.5
OpenBSD OpenBSD=3.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2230?
CVE-2004-2230 is categorized as a moderate severity vulnerability due to its potential for denial of service and memory corruption.
2
How do I fix CVE-2004-2230?
To fix CVE-2004-2230, you should upgrade to a patched version of OpenBSD, specifically version 3.7 or later.
3
What versions of OpenBSD are affected by CVE-2004-2230?
CVE-2004-2230 affects OpenBSD versions 3.4, 3.5, and 3.6.
4
What type of vulnerability is CVE-2004-2230?
CVE-2004-2230 is a heap-based buffer overflow vulnerability.
5
Who is impacted by CVE-2004-2230?
CVE-2004-2230 impacts local users of affected OpenBSD versions who can exploit IPSEC credentials.