10
CVSSv2

CVE-2004-0607

Published: 06/12/2004 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote malicious users to bypass authentication.

Vulnerable Product Search on Vulmon Subscribe to Product

ipsec-tools ipsec-tools 0.3 rc4

ipsec-tools ipsec-tools 0.3 rc2

kame racoon

kame racoon 2004-04-05

ipsec-tools ipsec-tools 0.3.2

ipsec-tools ipsec-tools 0.3 rc5

kame racoon 2003-07-11

ipsec-tools ipsec-tools 0.3.1

kame racoon 2004-05-03

ipsec-tools ipsec-tools 0.3 rc1

kame racoon 2004-04-07b

ipsec-tools ipsec-tools 0.3

ipsec-tools ipsec-tools 0.3 rc3

redhat enterprise linux desktop 3.0

redhat enterprise linux 3.0

Vendor Advisories

Synopsis ipsec-tools security update Type/Severity Security Advisory: Important Topic An updated ipsec-tools package that fixes verification of X509certificates in racoon is now available Description IPSEC uses strong cryptography to provide both authentication andencryption servicesWhen ...