CVE-2008-4551: Null Pointer Dereference
strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKESAINIT message with a large number of NULL values in a Key Exchange payload, which triggers a NULL pointer dereference for the return value of the mpzexport function in the GNU Multiprecision Library (GMP).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4551?
CVE-2008-4551 has a severity rating of medium, as it can lead to denial of service conditions.
What versions of strongSwan are affected by CVE-2008-4551?
CVE-2008-4551 affects strongSwan versions 4.2.6 and earlier.
How do I fix CVE-2008-4551?
To fix CVE-2008-4551, upgrade your strongSwan installation to a version later than 4.2.6.
What is the impact of CVE-2008-4551?
The impact of CVE-2008-4551 is a potential crash of the strongSwan daemon, causing service disruption.
Is there a workaround for CVE-2008-4551?
Currently, there is no specific workaround for CVE-2008-4551 other than applying the relevant updates.