5
CVSSv2

CVE-2008-4551

Published: 14/10/2008 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

strongSwan 4.2.6 and previous versions allows remote malicious users to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NULL values in a Key Exchange payload, which triggers a NULL pointer dereference for the return value of the mpz_export function in the GNU Multiprecision Library (GMP).

Vulnerable Product Search on Vulmon Subscribe to Product

strongswan strongswan 4.2.0

strongswan strongswan 4.1.11

strongswan strongswan 4.1.4

strongswan strongswan 4.1.3

strongswan strongswan 4.0.4

strongswan strongswan 4.0.3

strongswan strongswan 4.0.2

strongswan strongswan 2.6.1

strongswan strongswan 2.6.0

strongswan strongswan 2.5.1

strongswan strongswan 2.5.0

strongswan strongswan 2.3.1

strongswan strongswan 2.2.2

strongswan strongswan 2.1.1

strongswan strongswan 2.1.0

strongswan strongswan 4.2.4

strongswan strongswan 4.2.3

strongswan strongswan 4.1.8

strongswan strongswan 4.1.7

strongswan strongswan 4.1.0

strongswan strongswan 4.0.7

strongswan strongswan 2.7.0

strongswan strongswan 2.6.4

strongswan strongswan 2.5.5

strongswan strongswan 2.5.4

strongswan strongswan 2.4.1

strongswan strongswan 2.4.0

strongswan strongswan 2.1.5

strongswan strongswan 2.1.4

strongswan strongswan 2.0.0

strongswan strongswan

strongswan strongswan 4.2.2

strongswan strongswan 4.2.1

strongswan strongswan 4.1.6

strongswan strongswan 4.1.5

strongswan strongswan 4.0.6

strongswan strongswan 4.0.5

strongswan strongswan 2.6.3

strongswan strongswan 2.6.2

strongswan strongswan 2.5.3

strongswan strongswan 2.5.2

strongswan strongswan 2.4.0a

strongswan strongswan 2.3.2

strongswan strongswan 2.3.0

strongswan strongswan 2.1.3

strongswan strongswan 2.1.2

strongswan strongswan 4.2.5

strongswan strongswan 4.1.10

strongswan strongswan 4.1.9

strongswan strongswan 4.1.2

strongswan strongswan 4.1.1

strongswan strongswan 4.0.1

strongswan strongswan 4.0.0

strongswan strongswan 2.5.7

strongswan strongswan 2.5.6

strongswan strongswan 2.4.3

strongswan strongswan 2.4.2

strongswan strongswan 2.2.1

strongswan strongswan 2.2.0

strongswan strongswan 2.0.2

strongswan strongswan 2.0.1

Vendor Advisories

Debian Bug report logs - #502676 CVE-2008-4551: DoS Package: strongswan; Maintainer for strongswan is strongSwan Maintainers <pkg-swan-devel@listsaliothdebianorg>; Source for strongswan is src:strongswan (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sun, 19 Oct 2008 01:00:0 ...