PublicDate: 2005-08-05 04:00:00 UTC Candidate: CVE-2005-2359 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2359 Description: The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_kfreebsd-5: released (5.4-12) edgy_kfreebsd-5: released (5.4-12) feisty_kfreebsd-5: released (5.4-12) devel_kfreebsd-5: released (5.4-12) upstream_kfreebsd-5: needs-triage