CVE-2002-0666

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/11/2002
Last modified:
03/04/2025

Description

IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frees_wan:frees_wan:1.9:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:frees_wan:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:frees_wan:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:frees_wan:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:frees_wan:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:frees_wan:1.9.5:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:frees_wan:1.9.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.2:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.6:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.6:release:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.6:stable:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5:*:sh3:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5:*:x86:*:*:*:*:*