PT-2007-1024 · Unknown+1 · Ipsec-Tools+1

Publicado

2007-04-10

·

Atualizado

2017-10-11

·

CVE-2007-1841

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: ipsec-tools versions prior to 0.6.7
Description: The issue affects the ipsec-tools package, allowing remote attackers to cause a denial of service, leading to disruption of protected information. This can be achieved through crafted messages, specifically DELETE (ISAKMP NPTYPE D) and NOTIFY (ISAKMP NPTYPE N) messages, exploiting the isakmp info recv function in src/racoon/isakmp inf.c in racoon.
Recommendations: For versions prior to 0.6.7, update to version 0.6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the isakmp info recv function in src/racoon/isakmp inf.c until a patch is available. Additionally, limiting the handling of DELETE (ISAKMP NPTYPE D) and NOTIFY (ISAKMP NPTYPE N) messages can help minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-02831
BDU:2015-09571
CVE-2007-1841
DSA-1299-1
DTSA-42-1
RHSA-2007:0342
RHSA-2007_0342

Produtos afetados

Red Hat
Ipsec-Tools