Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian: DSA-1804-1 Moderate: ipsec-tools Denial Of Service Exploit

debian
Calendar Grey May 20, 2009
Debian Logo
A new security bulletin details essential ipsec-tools patches that address denial of service vulnerabilities in Debian systems, emphasizing urgent action for security.
Several remote vulnerabilities have been discovered in racoon, the Internet Key Exchange daemon of ipsec-tools

Summary

Several remote vulnerabilities have been discovered in racoon, the Internet Key
Exchange daemon of ipsec-tools. The The Common Vulnerabilities and Exposures
project identified the following problems:

Neil Kettle discovered a NULL pointer dereference on crafted fragmented packets
that contain no payload. This results in the daemon crashing which can be used
for denial of service attacks (CVE-2009-1574).

Various memory leaks in the X.509 certificate authentication handling and the
NAT-Traversal keepalive implementation can result in memory exhaustion and
thus denial of service (CVE-2009-1632).


For the oldstable distribution (etch), this problem has been fixed in
version 0.6.6-3.1etch3.

For the stable distribution (lenny), this problem has been fixed in
version 0.7.1-1.3+lenny2.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 1:0.7.1-1.5.


We recommend that you upgrade your ipsec-tools packages.

Upgrad...

Read the Full Advisory

Package: ipsec-tools
CVE ID: CVE-2009-1574 CVE-2009-1632

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here