← Back

CVE-2002-0666

nvd nist
Published: Nov 4, 2002Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.

Affected (28)

Show all products
1 product
Frees Wan
2 products
Mac Os X
Mac Os X Server
1 product
Freebsd
1 product
Netbsd
Gnat Box Firmware
6 products
Bluefire Ix1035 Router
Ix1010
Ix1011
Ix1020
Ix1050
Ix2010
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Frees Wan
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4
Version 1.9.5
Version 1.9.6
Version 1.9
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.2
Version 10.2
Freebsd
Version 4.6
Version 4.6 release
Version 4.6 stable
Netbsd
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5
Version 1.5
Version 1.5
Version 1.6 beta
Configuration C
9 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.1
Version 3.2
Version 3.3
All versions
All versions
All versions
All versions
All versions
All versions

References (12)

ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-016.txt.asc (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-016.txt.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.