5
CVSSv2

CVE-2009-1957

Published: 08/06/2009 Updated: 14/10/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

charon/sa/ike_sa.c in the charon daemon in strongSWAN prior to 4.3.1 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

strongswan strongswan 2.1.3

strongswan strongswan 2.1.4

strongswan strongswan 2.4.0

strongswan strongswan 2.4.0a

strongswan strongswan 2.5.2

strongswan strongswan 2.5.3

strongswan strongswan 2.6.16

strongswan strongswan 2.6.2

strongswan strongswan 2.8.3

strongswan strongswan 2.8.4

strongswan strongswan 4.0.2

strongswan strongswan 4.0.3

strongswan strongswan 4.1.10

strongswan strongswan 4.1.11

strongswan strongswan 4.1.2

strongswan strongswan 4.1.9

strongswan strongswan 4.2.0

strongswan strongswan 2.0.0

strongswan strongswan 2.0.1

strongswan strongswan 2.1.5

strongswan strongswan 2.2.0

strongswan strongswan 2.4.1

strongswan strongswan 2.4.2

strongswan strongswan 2.5.4

strongswan strongswan 2.5.5

strongswan strongswan 2.6.20

strongswan strongswan 2.6.3

strongswan strongswan 2.6.4

strongswan strongswan 2.8.5

strongswan strongswan 2.8.6

strongswan strongswan 4.0.4

strongswan strongswan 4.0.5

strongswan strongswan 4.1.3

strongswan strongswan 4.1.5

strongswan strongswan 4.2.1

strongswan strongswan 4.2.10

strongswan strongswan 2.1.1

strongswan strongswan 2.1.2

strongswan strongswan 2.3.1

strongswan strongswan 2.3.2

strongswan strongswan 2.5.0

strongswan strongswan 2.5.1

strongswan strongswan 2.6.0

strongswan strongswan 2.6.1

strongswan strongswan 2.8.1

strongswan strongswan 2.8.2

strongswan strongswan 4.0.0

strongswan strongswan 4.0.1

strongswan strongswan 4.1.0

strongswan strongswan 4.1.1

strongswan strongswan 4.1.7

strongswan strongswan 4.1.8

strongswan strongswan 2.0.2

strongswan strongswan 2.1.0

strongswan strongswan 2.2.1

strongswan strongswan 2.2.2

strongswan strongswan 2.3.0

strongswan strongswan 2.4.3

strongswan strongswan 2.4.4

strongswan strongswan 2.5.6

strongswan strongswan 2.5.7

strongswan strongswan 2.7.0

strongswan strongswan 2.8.0

strongswan strongswan 2.8.7

strongswan strongswan 2.8.8

strongswan strongswan 4.0.6

strongswan strongswan 4.0.7

strongswan strongswan 4.1.4

strongswan strongswan 4.1.6

strongswan strongswan

Vendor Advisories

Debian Bug report logs - #531612 [SA35296] strongSwan Two Denial of Service Vulnerabilities Package: strongswan; Maintainer for strongswan is strongSwan Maintainers <pkg-swan-devel@listsaliothdebianorg>; Source for strongswan is src:strongswan (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <giuseppe@iuculanoit&g ...
Several remote vulnerabilities have been discovered in strongswan, an implementation of the IPSEC and IKE protocols The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1957 CVE-2009-1958 The charon daemon can crash when processing certain crafted IKEv2 packets (The old stable distribution (etch) was not a ...