Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-1632

Опубликовано: 22 апр. 2009
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4ipsec-toolsWill not fix
Red Hat Enterprise Linux 5ipsec-toolsFixedRHSA-2009:103618.05.2009

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=500886ipsec-tools: multiple memory leaks fixed in 0.7.2

EPSS

Процентиль: 88%
0.04307
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.

nvd
около 16 лет назад

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.

debian
около 16 лет назад

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attacke ...

github
около 3 лет назад

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.

oracle-oval
около 16 лет назад

ELSA-2009-1036: ipsec-tools security update (IMPORTANT)

EPSS

Процентиль: 88%
0.04307
Низкий

4.3 Medium

CVSS2