PT-2007-1024 · Unknown+1 · Ipsec-Tools+1

Published

2007-04-10

·

Updated

2017-10-11

·

CVE-2007-1841

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: ipsec-tools versions prior to 0.6.7
Description: The issue affects the ipsec-tools package, allowing remote attackers to cause a denial of service, leading to disruption of protected information. This can be achieved through crafted messages, specifically DELETE (ISAKMP NPTYPE D) and NOTIFY (ISAKMP NPTYPE N) messages, exploiting the isakmp info recv function in src/racoon/isakmp inf.c in racoon.
Recommendations: For versions prior to 0.6.7, update to version 0.6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the isakmp info recv function in src/racoon/isakmp inf.c until a patch is available. Additionally, limiting the handling of DELETE (ISAKMP NPTYPE D) and NOTIFY (ISAKMP NPTYPE N) messages can help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02831
BDU:2015-09571
CVE-2007-1841
DSA-1299-1
DTSA-42-1
RHSA-2007:0342
RHSA-2007_0342

Affected Products

Red Hat
Ipsec-Tools