The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freebsd | Freebsd | 5.3 (including) | 5.3 (including) |
Freebsd | Freebsd | 5.4 (including) | 5.4 (including) |
Kfreebsd-5 | Ubuntu | dapper | * |
Kfreebsd-5 | Ubuntu | devel | * |
Kfreebsd-5 | Ubuntu | edgy | * |
Kfreebsd-5 | Ubuntu | feisty | * |