7.8
CVSSv2

CVE-2008-3652

Published: 13/08/2008 Updated: 13/02/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which allows remote malicious users to cause a denial of service (resource consumption).

Vulnerable Product Search on Vulmon Subscribe to Product

ipsec-tools ipsec-tools

Vendor Advisories

Debian Bug report logs - #501026 ipsec-tools: CVE-2008-3652 denial of service for authenticated attackers Package: ipsec-tools; Maintainer for ipsec-tools is ipsec-tools packagers <team+ipsec-tools@trackerdebianorg>; Source for ipsec-tools is src:ipsec-tools (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg ...
It was discovered that there were multiple ways to leak memory during the IKE negotiation when handling certain packets If a remote attacker sent repeated malicious requests, the “racoon” key exchange server could allocate large amounts of memory, possibly leading to a denial of service ...