CVE-2004-0369
Summary
| CVE | CVE-2004-0369 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2017-07-11 01:30:00 UTC |
| Description | Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Entrust | Entrust Libkmp Isakmp Library | All | All | All | All |
| Application | Entrust | Entrust Libkmp Isakmp Library | All | All | All | All |
| Application | Symantec | Enterprise Firewall | 7.0 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 7.0.4 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 7.0.4 | All | windows_2000_nt | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | windows_2000_nt | All |
| Application | Symantec | Enterprise Firewall | 7.0 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 7.0.4 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 7.0.4 | All | windows_2000_nt | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | windows_2000_nt | All |
| Hardware | Symantec | Gateway Security 5300 | 1.0 | All | All | All |
| Hardware | Symantec | Gateway Security 5300 | 1.0 | All | All | All |
| Hardware | Symantec | Gateway Security 5400 | 2.0 | All | All | All |
| Hardware | Symantec | Gateway Security 5400 | 2.0 | All | All | All |
| Application | Symantec | Velociraptor | 1.5 | All | All | All |
| Application | Symantec | Velociraptor | 1.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| AusCERT - ESB-2004.0538 -- SYM04-012 -- Symantec IPsec/ISAKMP VPN Buffer Overflow | AUSCERT | www.auscert.org.au | Vendor Advisory |
| O-206: Entrust LibKmp Library Vulnerabilities | CIAC | www.ciac.org | Vendor Advisory |
| Symantec IPsec/ISAKMP VPN Buffer Overflow | CONFIRM | securityresponse.symantec.com | Vendor Advisory |
| 20040826 Entrust LibKmp Library Buffer Overflow | ISS | xforce.iss.net | Patch, Vendor Advisory |
| Entrust LibKMP ISAKMP Library Remote IPsec/ISAKMP Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.