LWN.net Logo

isakmpd: programming error

Package(s):isakmpd CVE #(s):CVE-2006-4436
Created:September 13, 2006 Updated:September 13, 2006
Description: A flaw has been found in isakmpd, OpenBSD's implementation of the Internet Key Exchange protocol, that caused Security Associations to be created with a replay window of 0 when isakmpd was acting as the responder during SA negotiation. This could allow an attacker to re-inject sniffed IPsec packets, which would not be checked against the replay counter.
Alerts:
Debian DSA-1175-1 2006-09-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds