The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.
2004-12-06T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ipsec-tools | ipsec-tools | 0.3 | Yes |
Application | ipsec-tools | ipsec-tools | 0.3.1 | Yes |
Application | ipsec-tools | ipsec-tools | 0.3.2 | Yes |
Application | ipsec-tools | ipsec-tools | 0.3_rc1 | Yes |
Application | ipsec-tools | ipsec-tools | 0.3_rc2 | Yes |
Application | ipsec-tools | ipsec-tools | 0.3_rc3 | Yes |
Application | ipsec-tools | ipsec-tools | 0.3_rc4 | Yes |
Application | ipsec-tools | ipsec-tools | 0.3_rc5 | Yes |
Application | kame | racoon | * | Yes |
Application | kame | racoon | 2003-07-11 | Yes |
Application | kame | racoon | 2004-04-05 | Yes |
Application | kame | racoon | 2004-04-07b | Yes |
Application | kame | racoon | 2004-05-03 | Yes |
Operating System | redhat | enterprise_linux | 3.0 | Yes |
Operating System | redhat | enterprise_linux | 3.0 | Yes |
Operating System | redhat | enterprise_linux | 3.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 3.0 | Yes |