|
|
| |
|
| |
isakmpd: programming error
| Package(s): | isakmpd |
CVE #(s): | CVE-2006-4436
|
| Created: | September 13, 2006 |
Updated: | September 13, 2006 |
| Description: |
A flaw has been found in isakmpd, OpenBSD's implementation of the
Internet Key Exchange protocol, that caused Security Associations to be
created with a replay window of 0 when isakmpd was acting as the
responder during SA negotiation. This could allow an attacker to
re-inject sniffed IPsec packets, which would not be checked against the
replay counter. |
| Alerts: |
|
( Log in to post comments)
|
|
|