Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10396

Опубликовано: 02 дек. 2016
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ipsec-toolsWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1470232ipsec-tools: Parsing and storing ISAKMP fragments in malicious order can exhaust resources

EPSS

Процентиль: 84%
0.02076
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

CVSS3: 7.5
nvd
больше 8 лет назад

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

CVSS3: 7.5
debian
больше 8 лет назад

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable ...

suse-cvrf
почти 8 лет назад

Security update for ipsec-tools

suse-cvrf
почти 8 лет назад

Security update for ipsec-tools

EPSS

Процентиль: 84%
0.02076
Низкий

7.5 High

CVSS3