IPsec-Tools Memory Leak in Processing Invalid Proposals Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1020667
|
|
SecurityTracker URL: http://securitytracker.com/id?1020667
|
|
CVE Reference: CVE-2008-3651
(Links to External Site)
|
Updated: Aug 13 2008
|
Original Entry Date: Aug 12 2008
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 0.7.1
|
Description: A vulnerability was reported in IPsec-Tools. A remote user can cause denial of service conditions.
A remote user can send a specially crafted proposal to cause the target service to consume excessive memory.
|
Impact: A remote user can cause the target service to consume excessive memory.
|
Solution: The vendor has issued a fixed version (0.7.1), available at:
http://sourceforge.net/project/showfiles.php?group_id=74601&package_id=74949&release_id=615380&abmode=1
|
Vendor URL: ipsec-tools.sourceforge.net/ (Links to External Site)
|
Cause: Resource error
|
Underlying OS: Linux (Any), UNIX (Any)
|
Reported By: VANHULLEBUS Yvan <vanhu@nohost.nodomain>
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: 2008-07-24 08:45
From: VANHULLEBUS Yvan <vanhu@nohost.nodomain>
Subject: [Ipsec-tools-announce] Ipsec-tools 0.7.1 released
|
Hi all.
Ipsec-tools 0.7.1 is out, with some fixes and features, which includes
a fix for memory leak when receiving invalid proposals.
As this leak may lead to a DoS (it will take time.... but it can be
done in some configurations), everybody is advised to update to this
version ASAP.
Archives are available here
ftp://ftp.netbsd.org/pub/NetBSD/misc/ipsec-tools/0.7/ipsec-tools-0.7.1.tar.bz2
(please have a look at http://www.netbsd.org/mirrors/#ftp).
and soon here:
http://prdownloads.sourceforge.net/ipsec-tools/ipsec-tools-0.7.1.tar.bz2
Yvan, ipsec-tools developer team.
-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys-and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Ipsec-tools-announce mailing list
Ipsec-tools-announce@li...
https://lists.sourceforge.net/lists/listinfo/ipsec-tools-announce
|
|