CVE

Id
5056  
CVE No.
CVE-2002-0666  
Status
Candidate  
Description
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.  
Phase
Modified (20050601)  
Votes
ACCEPT(3) Baker, Cole, Frech | NOOP(3) Christey, Cox, Wall  
Comments
Christey> DEBIAN:DSA-201