// For flags

CVE-2009-1632

ipsec-tools: multiple memory leaks fixed in 0.7.2

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.

Múltiples fugas de memoria en Ipsec-tools versiones anteriores a v0.7.2 permite a atacantes remotos provocar una denegación de servicio (consumo de memoria) a través de vectores envueltos (1) en la verificación de firma durante la autenticación de usuarios con certificados X.509, relacionado con la función eay_check_x509sign en src/racoon/crypto_openssl.c; y (2) la implementación NAT-Traversal (aka NAT-T) keepalive, relacionado con src/racoon/nattraversal.c.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-05-14 CVE Reserved
  • 2009-05-14 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
  • CWE-401: Missing Release of Memory after Effective Lifetime
CAPEC
References (28)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
<= 0.7.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version " <= 0.7.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc1
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc2
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc3
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc4
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc5
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc5
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc5"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.4"
rc1
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.5
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.5"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.5.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.5.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.5.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.5.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.5
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.5"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.6
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.6"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.7
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.7"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.7
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.7"
-
Affected