FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0905

This CVE name corresponds to:

Entered Topic
2006-03-24 ipsec -- reply attack vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0905
Phase Assigned(20060228)

Description

A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.

References

Source Reference
FREEBSD FreeBSD-SA-06:11
NETBSD NetBSD-SA2006-011
BID 17191
OSVDB 24068
SECTRACK 1015809
SECUNIA 19366
XF bsd-ipsec-replay(25398)