Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
ftp://patches.sgi.com/support/free/security/advisories/20040506-01-U.asc
http://marc.info/?l=bugtraq&m=108369640424244&w=2
http://secunia.com/advisories/11410
http://secunia.com/advisories/11877
http://security.gentoo.org/glsa/glsa-200404-17.xml
http://securitytracker.com/id?1009937
http://sourceforge.net/project/shownotes.php?release_id=232288
http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&r2=1.181
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069
http://www.redhat.com/support/errata/RHSA-2004-165.html
http://www.securityfocus.com/bid/10172
http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/15893
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11220
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A984
Source: MITRE
Published: 2004-06-01
Updated: 2017-10-11
Type: NVD-CWE-Other
Base Score: 5
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 10
Severity: MEDIUM
OR
cpe:2.3:a:kame:racoon:*:*:*:*:*:*:*:* versions up to 2004-04-08a (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
19124 | FreeBSD : racoon remote denial of service vulnerability (ISAKMP header length field) (ccd698df-8e20-11d8-90d1-0020ed76ef5a) | Nessus | FreeBSD Local Security Checks | medium |
14482 | GLSA-200404-17 : ipsec-tools and iputils contain a remote DoS vulnerability | Nessus | Gentoo Local Security Checks | medium |
14168 | Mandrake Linux Security Advisory : ipsec-tools (MDKSA-2004:069) | Nessus | Mandriva Local Security Checks | high |
13707 | Fedora Core 2 : ipsec-tools-0.2.5-2 (2004-132) | Nessus | Fedora Local Security Checks | medium |
12488 | RHEL 3 : ipsec-tools (RHSA-2004:165) | Nessus | Red Hat Local Security Checks | high |