Cisco VPN Client IKE packet payload buffer overflow

cisco-vpn-ike-payload-bo (9820) The risk level is classified as LowLow Risk

Description:

The Cisco Virtual Private Network (VPN) Client software is vulnerable to a denial of service attack, caused by a buffer overflow in the handling of malformed Internet Key Exchange (IKE) packets. By sending a specially-crafted IKE packet with more than 57 payloads, a remote attacker could overflow a buffer to cause the Cisco VPN Client to stop functioning properly.


Consequences:

Denial of Service

Remedy:

Upgrade to the latest version of Cisco VPN Client software (3.6 or later), as listed in Cisco Security Advisory: Cisco VPN Client Multiple Vulnerabilities. See References.

For FreeBSD Ports Collection:
Upgrade to the latest ports collection, as listed in FreeBSD Security Notice FreeBSD-SN-02:05. See References.

For OpenBSD 3.1:
Apply the patch for this vulnerability, as listed in OpenBSD 010: RELIABILITY FIX: July 5, 2002. See References.

References:

Platforms Affected:

  • Cisco VPN Client 3.5.1
  • Cisco VPN Client 3.5.2

Reported:

Aug 12, 2002

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page