Vulnerabilities > CVE-2006-4436 - Unspecified vulnerability in Openbsd 3.8/3.9
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN openbsd
nessus
Summary
isakmpd in OpenBSD 3.8, 3.9, and possibly earlier versions, creates Security Associations (SA) with a replay window of size 0 when isakmpd acts as a responder during SA negotiation, which allows remote attackers to replay IPSec packets and bypass the replay protection.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1175.NASL |
description | A flaw has been found in isakmpd, OpenBSD |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22717 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22717 |
title | Debian DSA-1175-1 : isakmpd - programming error |
code |
|
References
- http://secunia.com/advisories/21652
- http://secunia.com/advisories/21652
- http://secunia.com/advisories/21905
- http://secunia.com/advisories/21905
- http://securitytracker.com/id?1016757
- http://securitytracker.com/id?1016757
- http://www.debian.org/security/2006/dsa-1175
- http://www.debian.org/security/2006/dsa-1175
- http://www.openbsd.org/errata.html#isakmpd
- http://www.openbsd.org/errata.html#isakmpd
- http://www.openbsd.org/errata38.html#isakmpd
- http://www.openbsd.org/errata38.html#isakmpd
- http://www.osvdb.org/28194
- http://www.osvdb.org/28194
- http://www.securityfocus.com/bid/19712
- http://www.securityfocus.com/bid/19712
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28645
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28645