CVE-2004-0221

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
04/05/2004
Last modified:
03/04/2025

Description

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* 3.4 (including)