CVE-2008-3651: Infoleak
ipsec-tools upstream released 0.7.1 including a fix for a memory leak in racoon daemon triggered by the invalid proposals, possibly resulting in a denial of service once daemon runs out of memory.
References: http://marc.info/?l=ipsec-tools-devel&m=121688914101709&w=2 http://bugs.gentoo.org/showbug.cgi?id=232831
Upstream patch: http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/proposal.c.diff?r1=1.15&r2=1.16&f=h http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/ChangeLog.diff?r1=1.169&r2=1.170&f=h
Other sources
Memory leak in racoon/proposal.c in the racoon daemon in ipsec-tools before 0.7.1 allows remote authenticated users to cause a denial of service (memory consumption) via invalid proposals.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3651?
CVE-2008-3651 is classified as a medium severity vulnerability due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2008-3651?
To fix CVE-2008-3651, upgrade ipsec-tools to version 0.7.1 or later.
What type of vulnerability is CVE-2008-3651?
CVE-2008-3651 is a memory leak vulnerability in the racoon daemon of ipsec-tools.
Which software versions are affected by CVE-2008-3651?
CVE-2008-3651 affects ipsec-tools versions before 0.7.1 including 0.2.5, 0.3.3, 0.6.5 and others.
What impact does CVE-2008-3651 have on systems?
The impact of CVE-2008-3651 is a denial of service condition due to excessive memory consumption from invalid proposals.