First published: Sun Dec 04 2005(Updated: )
The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Astaro Security Gateway | =6.101 | |
Sophos Astaro Security Gateway | =6.001 | |
Sophos Astaro Security Gateway | =6.002 |
http://www.astaro.org/showflat.php?Cat=&Number=63958&page=0&view=collapsed&sb=5&o=&fpart=1#63958
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3985 has a high severity as it allows for potential denial of service and arbitrary code execution.
To fix CVE-2005-3985, upgrade Astaro Security Linux to version 6.102 or later.
CVE-2005-3985 affects Astaro Security Linux versions 6.001, 6.002, and 6.101.
Yes, CVE-2005-3985 can be exploited remotely through crafted IKE packets.
Yes, the PROTOS ISAKMP Test Suite demonstrates an exploit for CVE-2005-3985.