LWN.net Logo

ipsec-tools: denial of service

Package(s):ipsec-tools CVE #(s):CVE-2009-1632
Created:May 18, 2009 Updated:July 3, 2009
Description:

From the Mandriva advisory:

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c (CVE-2009-1632).

Alerts:
SuSE SUSE-SR:2009:012 2009-07-03
Ubuntu USN-785-1 2009-06-09
Gentoo 200905-03 2009-05-24
Debian DSA-1804-1 2009-05-20
CentOS CESA-2009:1036 2009-05-19
Fedora FEDORA-2009-4394 2009-05-08
Fedora FEDORA-2009-4298 2009-05-06
Fedora FEDORA-2009-4291 2009-05-06
Red Hat RHSA-2009:1036-01 2009-05-18
Mandriva MDVSA-2009:114 2009-05-18

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds