CVE-2005-0398: Medium severity KAME Racoon vulnerability
Published Mar 14, 2005
·Updated
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
Affected Software
33 affected components
KAME Racoon=2005-02-14
KAME Racoon=2005-02-28
SGI ProPack=3.0
Ipsec-tools Ipsec-tools=0.5
KAME Racoon=2004-04-05
KAME Racoon=2005-01-31
Ipsec-tools Ipsec-tools=0.3.3
KAME Racoon=2003-07-11
KAME Racoon=2005-01-03
KAME Racoon=2005-02-21
KAME Racoon=2005-01-10
KAME Racoon=2004-05-03
KAME Racoon=2004-04-07b
KAME Racoon=2005-01-24
KAME Racoon=2005-02-07
KAME Racoon=2005-03-07
KAME Racoon=2005-01-17
redhat Enterprise Linux=4.0
SUSE SuSE Linux=9.2
redhat Enterprise Linux Desktop=3.0
SUSE SuSE Linux=9.1
redhat Enterprise Linux=4.0
redhat Enterprise Linux=3.0
Altlinux Alt Linux=2.3
SUSE SuSE Linux
SUSE SuSE Linux=9.1
redhat Enterprise Linux=4.0
Altlinux Alt Linux=2.3
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux Desktop=4.0
SUSE SuSE Linux
SUSE SuSE Linux=9.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 14, 2005
CVE Published
05:00 AM
Mar 26, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0398?
CVE-2005-0398 has a critical severity level due to the potential for causing a denial of service.
2
How do I fix CVE-2005-0398?
To fix CVE-2005-0398, update the KAME racoon daemon or ipsec-tools to the latest patched version.
3
What systems are affected by CVE-2005-0398?
CVE-2005-0398 affects various versions of KAME racoon and ipsec-tools, specifically those before version 0.5.
4
What types of attacks can exploit CVE-2005-0398?
CVE-2005-0398 can be exploited by sending malformed ISAKMP packets to the affected services.
5
Is CVE-2005-0398 still a threat today?
While CVE-2005-0398 is a historical vulnerability, if affected systems remain unpatched, it can still pose a threat.