IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Frees_wan | Frees_wan | 1.9 (including) | 1.9 (including) |
Frees_wan | Frees_wan | 1.9.1 (including) | 1.9.1 (including) |
Frees_wan | Frees_wan | 1.9.2 (including) | 1.9.2 (including) |
Frees_wan | Frees_wan | 1.9.3 (including) | 1.9.3 (including) |
Frees_wan | Frees_wan | 1.9.4 (including) | 1.9.4 (including) |
Frees_wan | Frees_wan | 1.9.5 (including) | 1.9.5 (including) |
Frees_wan | Frees_wan | 1.9.6 (including) | 1.9.6 (including) |