The Entrust LibKMP ISAKMP library is reported to be affected by a remote buffer overflow vulnerability. Malicious ISAKMP packets may trigger a buffer overrun in the affected library resulting in the corruption of process memory. It is reported that a remote attacker may exploit this condition to deny service to the Entrust library or to execute arbitrary code in the context of an implementation that uses the library.
Although unconfirmed, it is conjectured that this vulnerability may be related to the vulnerability described in BID 10273, as Checkpoint VPN-1 may use the affected library.
Vendor Status:
Symantec as issued an update for this vulnerablity