CVE-2009-1574

MEDIUM

Description

racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.

References

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705

http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html

http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html

http://secunia.com/advisories/35113

http://secunia.com/advisories/35153

http://secunia.com/advisories/35159

http://secunia.com/advisories/35212

http://secunia.com/advisories/35404

http://secunia.com/advisories/35685

http://security.gentoo.org/glsa/glsa-200905-03.xml

http://sourceforge.net/project/shownotes.php?group_id=74601&release_id=677611

http://support.apple.com/kb/HT3937

http://support.apple.com/kb/HT4298

http://www.debian.org/security/2009/dsa-1804

http://www.mandriva.com/security/advisories?name=MDVSA-2009:112

http://www.openwall.com/lists/oss-security/2009/04/29/6

http://www.openwall.com/lists/oss-security/2009/05/04/3

http://www.redhat.com/support/errata/RHSA-2009-1036.html

http://www.securityfocus.com/bid/34765

http://www.ubuntu.com/usn/USN-785-1

http://www.vupen.com/english/advisories/2009/3184

https://bugzilla.redhat.com/show_bug.cgi?id=497990

https://exchange.xforce.ibmcloud.com/vulnerabilities/50412

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9624

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00725.html

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00746.html

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00789.html

Details

Source: MITRE

Published: 2009-05-06

Updated: 2017-09-29

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (27 total)

IDNameProductFamilySeverity
79457OracleVM 2.1 : ipsec-tools (OVMSA-2009-0010)NessusOracleVM Local Security Checks
high
67859Oracle Linux 5 : ipsec-tools (ELSA-2009-1036)NessusOracle Linux Local Security Checks
medium
60585Scientific Linux Security Update : ipsec-tools on SL5.x i386/x86_64NessusScientific Linux Local Security Checks
medium
51759SuSE 10 Security Update : Novell ipsec tools (ZYPP Patch Number 6306)NessusSuSE Local Security Checks
medium
51342Apple Time Capsule and AirPort Base Station Firmware < 7.5.2 (APPLE-SA-2010-12-16-1)NessusMisc.
high
43749CentOS 5 : ipsec-tools (CESA-2009:1036)NessusCentOS Local Security Checks
medium
800795Mac OS X 10.6 < 10.6.2 Multiple VulnerabilitiesLog Correlation EngineOperating System Detection
high
5227Mac OS X 10.6 < 10.6.2 Multiple VulnerabilitiesNessus Network MonitorGeneric
critical
42434Mac OS X 10.6.x < 10.6.2 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
42433Mac OS X Multiple Vulnerabilities (Security Update 2009-006)NessusMacOS X Local Security Checks
critical
42025openSUSE 10 Security Update : novell-ipsec-tools (novell-ipsec-tools-6307)NessusSuSE Local Security Checks
medium
41523SuSE 10 Security Update : ipsec-tools (ZYPP Patch Number 6301)NessusSuSE Local Security Checks
medium
41440SuSE 11 Security Update : Novell ipsec tools (SAT Patch Number 1006)NessusSuSE Local Security Checks
medium
41403SuSE 11 Security Update : ipsec-tools (SAT Patch Number 998)NessusSuSE Local Security Checks
medium
40283openSUSE Security Update : novell-ipsec-tools (novell-ipsec-tools-1007)NessusSuSE Local Security Checks
medium
40233openSUSE Security Update : ipsec-tools (ipsec-tools-996)NessusSuSE Local Security Checks
medium
40081openSUSE Security Update : novell-ipsec-tools (novell-ipsec-tools-1007)NessusSuSE Local Security Checks
medium
39993openSUSE Security Update : ipsec-tools (ipsec-tools-996)NessusSuSE Local Security Checks
medium
39514openSUSE 10 Security Update : ipsec-tools (ipsec-tools-6302)NessusSuSE Local Security Checks
medium
39353Ubuntu 6.06 LTS / 8.04 LTS / 8.10 / 9.04 : ipsec-tools vulnerabilities (USN-785-1)NessusUbuntu Local Security Checks
medium
38884GLSA-200905-03 : IPSec Tools: Denial of ServiceNessusGentoo Local Security Checks
medium
38861Debian DSA-1804-1 : ipsec-tools - NULL pointer dereference, memory leaksNessusDebian Local Security Checks
medium
38819RHEL 5 : ipsec-tools (RHSA-2009:1036)NessusRed Hat Local Security Checks
medium
38811Fedora 11 : ipsec-tools-0.7.2-1.fc11 (2009-4394)NessusFedora Local Security Checks
medium
38810Fedora 10 : ipsec-tools-0.7.2-1.fc10 (2009-4298)NessusFedora Local Security Checks
medium
38809Fedora 9 : ipsec-tools-0.7.2-1.fc9 (2009-4291)NessusFedora Local Security Checks
medium
38767Mandriva Linux Security Advisory : ipsec-tools (MDVSA-2009:112-1)NessusMandriva Local Security Checks
medium