PT-2008-1043 · Ipsec Tools+1 · Ipsec-Tools+1

Nico Golde

·

Publicado

2008-08-13

·

Atualizado

2025-03-27

·

CVE-2008-3652

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ipsec-tools versions prior to 0.7.1 ipsec-tools version 0.3.3 ipsec-tools version 0.2.5
Description The issue is related to multiple vulnerabilities in the ipsec-tools package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, in the src/racoon/handler.c file of racoon in ipsec-tools, an "orphaned ph1" (phase 1) handle is not removed when initiated remotely, allowing remote attackers to cause a denial of service through resource consumption.
Recommendations For ipsec-tools versions prior to 0.7.1, update to version 0.7.1 or later. For ipsec-tools version 0.3.3, update to a version later than 0.3.3. For ipsec-tools version 0.2.5, update to a version later than 0.2.5. As a temporary workaround, consider restricting access to the racoon handler to minimize the risk of exploitation.

Correção

DoS

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06100
BDU:2015-06101
BDU:2015-08447
BDU:2015-08448
BDU:2015-09354
CVE-2008-3652
RHSA-2008:0849
RHSA-2008_0849

Produtos afetados

Red Hat
Ipsec-Tools