CVE Vulnerabilities

CVE-2002-0414

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd4.2 (including)4.2 (including)
FreebsdFreebsd4.3 (including)4.3 (including)
FreebsdFreebsd4.4 (including)4.4 (including)
FreebsdFreebsd4.5 (including)4.5 (including)
NetbsdNetbsd1.5 (including)1.5 (including)
NetbsdNetbsd1.5.1 (including)1.5.1 (including)
NetbsdNetbsd1.5.2 (including)1.5.2 (including)
OpenbsdOpenbsd2.6 (including)2.6 (including)
OpenbsdOpenbsd2.7 (including)2.7 (including)

References