Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
References
Link | Resource |
---|---|
http://securityresponse.symantec.com/avcenter/security/Content/2005.11.21.html | Patch Vendor Advisory |
http://securitytracker.com/id?1015249 | Patch |
http://securitytracker.com/id?1015248 | Patch |
http://securitytracker.com/id?1015247 | Patch |
http://secunia.com/advisories/17684 | Patch Vendor Advisory |
http://www.vupen.com/english/advisories/2005/2517 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2005-11-22 16:03
Updated : 2011-03-07 18:27
NVD link : CVE-2005-3768
Mitre link : CVE-2005-3768
JSON object : View
CWE
Products Affected
symantec
- gateway_security_5310
- gateway_security_5300
- gateway_security_5400
- firewall_vpn_appliance_200
- enterprise_firewall
- gateway_security_5000_series
- gateway_security_400
- gateway_security_5100
- gateway_security_300
- firewall_vpn_appliance_100