VYPR
Unrated severityNVD Advisory· Published Dec 6, 2004· Updated Apr 16, 2026

CVE-2004-0607

CVE-2004-0607

Description

The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.

Affected products

17
  • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3_rc1:*:*:*:*:*:*:*
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3_rc2:*:*:*:*:*:*:*
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3_rc3:*:*:*:*:*:*:*
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3_rc4:*:*:*:*:*:*:*
    • cpe:2.3:a:ipsec-tools:ipsec-tools:0.3_rc5:*:*:*:*:*:*:*
  • Kame/Racoon5 versions
    cpe:2.3:a:kame:racoon:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:kame:racoon:*:*:*:*:*:*:*:*
    • cpe:2.3:a:kame:racoon:2003-07-11:*:*:*:*:*:*:*
    • cpe:2.3:a:kame:racoon:2004-04-05:*:*:*:*:*:*:*
    • cpe:2.3:a:kame:racoon:2004-04-07b:*:*:*:*:*:*:*
    • cpe:2.3:a:kame:racoon:2004-05-03:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:3.0:*:advanced_servers:*:*:*:*:*+ 2 more
    • cpe:2.3:o:redhat:enterprise_linux:3.0:*:advanced_servers:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:3.0:*:enterprise_server:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:3.0:*:workstation:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_desktop:3.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.