SUSE-SA:2005:020: ipsec-tools

medium Nessus Plugin ID 17671

Synopsis

The remote host is missing a vendor-supplied security patch

Description

The remote host is missing the patch for the advisory SUSE-SA:2005:020 (ipsec-tools).


Racoon is a ISAKMP key management daemon used in IPsec setups.

Sebastian Krahmer of the SUSE Security Team audited the daemon and found that it handles certain ISAKMP messages in a slightly wrong way, so that remote attackers can crash it via malformed ISAKMP packages.

This update fixes this problem.

This is tracked by the Mitre CVE ID CVE-2005-0398.

Solution

http://www.suse.de/security/advisories/2005_20_ipsec_tools.html

Plugin Details

Severity: Medium

ID: 17671

File Name: suse_SA_2005_020.nasl

Version: 1.11

Agent: unix

Published: 4/1/2005

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list

Reference Information

CVE: CVE-2005-0398