5
CVSSv2

CVE-2009-1958

Published: 08/06/2009 Updated: 14/10/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

charon/sa/tasks/child_create.c in the charon daemon in strongSWAN prior to 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote malicious users to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

strongswan strongswan 4.0.3

strongswan strongswan 4.1.10

strongswan strongswan 4.1.6

strongswan strongswan 4.1.7

strongswan strongswan 4.2.4

strongswan strongswan 4.2.5

strongswan strongswan

strongswan strongswan 2.4.0a

strongswan strongswan 2.1.4

strongswan strongswan 2.1.3

strongswan strongswan 2.3.1

strongswan strongswan 2.4.2

strongswan strongswan 2.4.3

strongswan strongswan 2.5.2

strongswan strongswan 4.1.0

strongswan strongswan 4.1.2

strongswan strongswan 4.1.5

strongswan strongswan 4.1.4

strongswan strongswan 4.2.10

strongswan strongswan 4.2.2

strongswan strongswan 4.2.3

strongswan strongswan 4.2.12

strongswan strongswan 4.2.11

strongswan strongswan 2.0.1

strongswan strongswan 2.0.0

strongswan strongswan 2.2.0

strongswan strongswan 2.3.2

strongswan strongswan 2.3.0

strongswan strongswan 2.5.4

strongswan strongswan 2.5.5

strongswan strongswan 2.6.16

strongswan strongswan 2.6.20

strongswan strongswan 2.6.4

strongswan strongswan 2.8.6

strongswan strongswan 4.0.0

strongswan strongswan 4.0.6

strongswan strongswan 4.1.1

strongswan strongswan 4.0.4

strongswan strongswan 4.1.3

strongswan strongswan 4.2.0

strongswan strongswan 4.2.1

strongswan strongswan 4.2.6

strongswan strongswan 4.2.13

strongswan strongswan 2.1.2

strongswan strongswan 2.0.2

strongswan strongswan 2.2.2

strongswan strongswan 2.2.1

strongswan strongswan 2.5.6

strongswan strongswan 2.5.7

strongswan strongswan 2.5.0

strongswan strongswan 2.5.1

strongswan strongswan 2.8.0

strongswan strongswan 2.6.1

strongswan strongswan 2.7.0

strongswan strongswan 2.8.8

strongswan strongswan 4.0.1

strongswan strongswan 2.8.7

strongswan strongswan 4.0.7

strongswan strongswan 4.1.11

strongswan strongswan 4.0.5

strongswan strongswan 4.1.8

strongswan strongswan 4.1.9

strongswan strongswan 4.2.8

strongswan strongswan 4.2.7

strongswan strongswan 4.0.2

strongswan strongswan 2.1.5

strongswan strongswan 2.1.1

strongswan strongswan 2.1.0

strongswan strongswan 2.4.0

strongswan strongswan 2.4.1

strongswan strongswan 2.5.3

strongswan strongswan 2.4.4

strongswan strongswan 2.8.1

strongswan strongswan 2.6.0

strongswan strongswan 2.8.3

strongswan strongswan 2.8.2

strongswan strongswan 2.6.2

strongswan strongswan 2.6.3

strongswan strongswan 2.8.5

strongswan strongswan 2.8.4

Vendor Advisories

Debian Bug report logs - #531612 [SA35296] strongSwan Two Denial of Service Vulnerabilities Package: strongswan; Maintainer for strongswan is strongSwan Maintainers <pkg-swan-devel@listsaliothdebianorg>; Source for strongswan is src:strongswan (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <giuseppe@iuculanoit&g ...
Several remote vulnerabilities have been discovered in strongswan, an implementation of the IPSEC and IKE protocols The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1957 CVE-2009-1958 The charon daemon can crash when processing certain crafted IKEv2 packets (The old stable distribution (etch) was not a ...