A programming error in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freebsd | Freebsd | 4.8 (including) | 4.8 (including) |
Freebsd | Freebsd | 4.8-pre-release (including) | 4.8-pre-release (including) |
Freebsd | Freebsd | 4.8-release_p7 (including) | 4.8-release_p7 (including) |
Freebsd | Freebsd | 4.8-releng (including) | 4.8-releng (including) |
Freebsd | Freebsd | 4.9 (including) | 4.9 (including) |
Freebsd | Freebsd | 4.9-pre-release (including) | 4.9-pre-release (including) |
Freebsd | Freebsd | 4.9-releng (including) | 4.9-releng (including) |
Freebsd | Freebsd | 4.10 (including) | 4.10 (including) |
Freebsd | Freebsd | 4.10-release (including) | 4.10-release (including) |
Freebsd | Freebsd | 4.10-release_p8 (including) | 4.10-release_p8 (including) |
Freebsd | Freebsd | 4.10-releng (including) | 4.10-releng (including) |
Freebsd | Freebsd | 4.11-release_p3 (including) | 4.11-release_p3 (including) |
Freebsd | Freebsd | 4.11-releng (including) | 4.11-releng (including) |
Freebsd | Freebsd | 4.11-stable (including) | 4.11-stable (including) |
Freebsd | Freebsd | 5.0 (including) | 5.0 (including) |
Freebsd | Freebsd | 5.0-alpha (including) | 5.0-alpha (including) |
Freebsd | Freebsd | 5.0-release_p14 (including) | 5.0-release_p14 (including) |
Freebsd | Freebsd | 5.0-releng (including) | 5.0-releng (including) |
Freebsd | Freebsd | 5.1 (including) | 5.1 (including) |
Freebsd | Freebsd | 5.1-alpha (including) | 5.1-alpha (including) |
Freebsd | Freebsd | 5.1-release (including) | 5.1-release (including) |
Freebsd | Freebsd | 5.1-release_p5 (including) | 5.1-release_p5 (including) |
Freebsd | Freebsd | 5.1-releng (including) | 5.1-releng (including) |
Freebsd | Freebsd | 5.2 (including) | 5.2 (including) |
Freebsd | Freebsd | 5.2.1-release (including) | 5.2.1-release (including) |
Freebsd | Freebsd | 5.2.1-releng (including) | 5.2.1-releng (including) |
Freebsd | Freebsd | 5.3 (including) | 5.3 (including) |
Freebsd | Freebsd | 5.3-release (including) | 5.3-release (including) |
Freebsd | Freebsd | 5.3-releng (including) | 5.3-releng (including) |
Freebsd | Freebsd | 5.3-stable (including) | 5.3-stable (including) |
Freebsd | Freebsd | 5.4-pre-release (including) | 5.4-pre-release (including) |
Freebsd | Freebsd | 5.4-release (including) | 5.4-release (including) |
Freebsd | Freebsd | 5.4-releng (including) | 5.4-releng (including) |
Freebsd | Freebsd | 5.4-stable (including) | 5.4-stable (including) |
Freebsd | Freebsd | 6.0-release (including) | 6.0-release (including) |
Freebsd | Freebsd | 6.0-stable (including) | 6.0-stable (including) |
Netbsd | Netbsd | 2.0 (including) | 2.0 (including) |
Netbsd | Netbsd | 3.0 (including) | 3.0 (including) |
Kfreebsd-5 | Ubuntu | dapper | * |
Kfreebsd-5 | Ubuntu | edgy | * |
Kfreebsd-5 | Ubuntu | feisty | * |
Kfreebsd-5 | Ubuntu | gutsy | * |
Kfreebsd-5 | Ubuntu | hardy | * |
Kfreebsd-5 | Ubuntu | intrepid | * |