PT-2004-1340 · Kame · Kame Ike Daemon

Itojun

·

Published

2004-02-19

·

Updated

2017-10-11

·

CVE-2004-0164

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions KAME IKE daemon (racoon) (affected versions not specified)
Description The issue arises from the KAME IKE daemon's (racoon) improper handling of hash values. This allows remote attackers to delete certificates by exploiting two specific message handling vulnerabilities in the isakmp.c and isakmp inf.c files. The first vulnerability involves a certain delete message, while the second involves a certain INITIAL-CONTACT message.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0164
RHSA-2004:165

Affected Products

Kame Ike Daemon