Vulnerability Details CVE-2002-0666
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2002-0666
-
cpe:2.3:a:frees_wan:frees_wan:1.9
-
cpe:2.3:a:frees_wan:frees_wan:1.9.1
-
cpe:2.3:a:frees_wan:frees_wan:1.9.2
-
cpe:2.3:a:frees_wan:frees_wan:1.9.3
-
cpe:2.3:a:frees_wan:frees_wan:1.9.4
-
cpe:2.3:a:frees_wan:frees_wan:1.9.5
-
cpe:2.3:a:frees_wan:frees_wan:1.9.6
-
cpe:2.3:h:global_technology_associates:gnat_box_firmware:3.1
-
cpe:2.3:h:global_technology_associates:gnat_box_firmware:3.2
-
cpe:2.3:h:global_technology_associates:gnat_box_firmware:3.3
-
cpe:2.3:h:nec:bluefire_ix1035_router:-
-
-
-
-
-
-
cpe:2.3:o:apple:mac_os_x:10.2
-
cpe:2.3:o:apple:mac_os_x_server:10.2
-
cpe:2.3:o:freebsd:freebsd:4.6
-
cpe:2.3:o:netbsd:netbsd:1.5
-
cpe:2.3:o:netbsd:netbsd:1.5.1
-
cpe:2.3:o:netbsd:netbsd:1.5.2
-
cpe:2.3:o:netbsd:netbsd:1.5.3
-
cpe:2.3:o:netbsd:netbsd:1.6