PGPFreeware Malformed IKE Response Packet Buffer Overflow Vulnerability
BID:5449
Info
PGPFreeware Malformed IKE Response Packet Buffer Overflow Vulnerability
| Bugtraq ID: | 5449 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2002 12:00AM |
| Updated: | Aug 12 2002 12:00AM |
| Credit: | This issue was announced by the CERT Coordination Center. Credit is given to Anton Rager of Avaya Communications. |
| Vulnerable: |
Network Associates PGP Freeware 7.0.3 |
| Not Vulnerable: | |
Discussion
PGPFreeware Malformed IKE Response Packet Buffer Overflow Vulnerability
The implementation of Internet Key Exchange (IKE) used by the PGPFreeware VPN client is reported to be prone to a buffer overflow when handling malformed IKE response packets. An attacker may potentially exploit this condition to execute arbitrary code on a client system or cause a denial of service.
Other vendor products are reported to be affected by similar issues. Bugtraq ID(s) 5440, 5441, 5443 describe similar issues with regards to the handling of malformed IKE response packets. There are currently not enough details available to determine if PGPFreeware is affected by any of these specific issues.
This issue was reported in PGPFreeware 7.03 running on Windows NT 4.0 SP6. Other versions and platforms may also be affected.
The implementation of Internet Key Exchange (IKE) used by the PGPFreeware VPN client is reported to be prone to a buffer overflow when handling malformed IKE response packets. An attacker may potentially exploit this condition to execute arbitrary code on a client system or cause a denial of service.
Other vendor products are reported to be affected by similar issues. Bugtraq ID(s) 5440, 5441, 5443 describe similar issues with regards to the handling of malformed IKE response packets. There are currently not enough details available to determine if PGPFreeware is affected by any of these specific issues.
This issue was reported in PGPFreeware 7.03 running on Windows NT 4.0 SP6. Other versions and platforms may also be affected.
Exploit / POC
PGPFreeware Malformed IKE Response Packet Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PGPFreeware Malformed IKE Response Packet Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PGPFreeware Malformed IKE Response Packet Buffer Overflow Vulnerability
References:
References:
- Vulnerability Note VU#287771 (CERT/CC)