|
The KAME-based IPsec implementation included in NetBSD was missing some packet length checks, and could be tricked into passing negative value as buffer length. By transmiting a specially-formed (very short) ESP packet, a malicious sender can cause a cause kernel panic on the victim node. |