// For flags

CVE-2009-1632

ipsec-tools: multiple memory leaks fixed in 0.7.2

Severity Score

10.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.

Múltiples fugas de memoria en Ipsec-tools versiones anteriores a v0.7.2 permite a atacantes remotos provocar una denegación de servicio (consumo de memoria) a través de vectores envueltos (1) en la verificación de firma durante la autenticación de usuarios con certificados X.509, relacionado con la función eay_check_x509sign en src/racoon/crypto_openssl.c; y (2) la implementación NAT-Traversal (aka NAT-T) keepalive, relacionado con src/racoon/nattraversal.c.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-05-14 CVE Reserved
  • 2009-05-14 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
  • CWE-401: Missing Release of Memory after Effective Lifetime
CAPEC
References (28)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
<= 0.7.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version " <= 0.7.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.2.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.2.4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc1
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc2
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc3
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc4
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3"
rc5
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.3_rc5
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.3_rc5"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.4"
rc1
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.5
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.5"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.5.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.5.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.5.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.5.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.1
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.1"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.2
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.2"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.3
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.3"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.4
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.4"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.5
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.5"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.6
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.6"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.6.7
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.6.7"
-
Affected
Ipsec-tools
Search vendor "Ipsec-tools"
Ipsec-tools
Search vendor "Ipsec-tools" for product "Ipsec-tools"
0.7
Search vendor "Ipsec-tools" for product "Ipsec-tools" and version "0.7"
-
Affected