5

CVE-2002-0666

IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Frees Wan ≫ Frees Wan Version 1.9
Frees Wan ≫ Frees Wan Version 1.9.1
Frees Wan ≫ Frees Wan Version 1.9.2
Frees Wan ≫ Frees Wan Version 1.9.3
Frees Wan ≫ Frees Wan Version 1.9.4
Frees Wan ≫ Frees Wan Version 1.9.5
Frees Wan ≫ Frees Wan Version 1.9.6
Apple ≫ macOS X Version 10.2
Apple ≫ macOS X Server Version 10.2
Freebsd ≫ Freebsd Version 4.6
Freebsd ≫ Freebsd Version 4.6 Update release
Freebsd ≫ Freebsd Version 4.6 Update stable
Netbsd ≫ Netbsd Version 1.5
Netbsd ≫ Netbsd Version 1.5 Edition sh3
Netbsd ≫ Netbsd Version 1.5 Edition x86
Netbsd ≫ Netbsd Version 1.5.1
Netbsd ≫ Netbsd Version 1.5.2
Netbsd ≫ Netbsd Version 1.5.3
Netbsd ≫ Netbsd Version 1.6 Update beta
Nec ≫ Ix1010
Nec ≫ Ix1011
Nec ≫ Ix1020
Nec ≫ Ix1050
Nec ≫ Ix2010
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.47% 0.825
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-016.txt.asc
http://razor.bindview.com/publish/advisories/adv_ipsec.html
Vendor Advisory
http://www.debian.org/security/2002/dsa-201
http://www.iss.net/security_center/static/10411.php
Vendor Advisory
http://www.kb.cert.org/vuls/id/459371
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/6011