Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10396

Опубликовано: 06 июл. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ipsec-tools:ipsec-tools:0.8.2:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02076
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-407

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

CVSS3: 7.5
redhat
около 9 лет назад

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

CVSS3: 7.5
debian
больше 8 лет назад

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable ...

suse-cvrf
почти 8 лет назад

Security update for ipsec-tools

suse-cvrf
почти 8 лет назад

Security update for ipsec-tools

EPSS

Процентиль: 84%
0.02076
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-407