CVE Vulnerabilities

CVE-2002-0414

Published: Aug 12, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 4.2 (including) 4.2 (including)
Freebsd Freebsd 4.3 (including) 4.3 (including)
Freebsd Freebsd 4.4 (including) 4.4 (including)
Freebsd Freebsd 4.5 (including) 4.5 (including)
Netbsd Netbsd 1.5 (including) 1.5 (including)
Netbsd Netbsd 1.5.1 (including) 1.5.1 (including)
Netbsd Netbsd 1.5.2 (including) 1.5.2 (including)
Openbsd Openbsd 2.6 (including) 2.6 (including)
Openbsd Openbsd 2.7 (including) 2.7 (including)

References