PT-2006-1948 · Freebsd+1 · Freebsd+1
Published
2006-03-23
·
Updated
2017-07-20
·
CVE-2006-0905
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 4.8 through 6.1-STABLE
NetBSD versions 2 through 3
Description
A programming error in the fast ipsec component does not properly update the sequence number associated with a Security Association. This allows packets to pass sequence number checks, enabling remote attackers to capture IPSec packets and conduct replay attacks.
Recommendations
For FreeBSD versions 4.8 through 6.1-STABLE, update the fast ipsec component to properly handle sequence number updates.
For NetBSD versions 2 through 3, update the fast ipsec component to properly handle sequence number updates.
As a temporary workaround, consider restricting access to the fast ipsec component to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Netbsd