CVE-2009-0267: Input Validation
libike in Sun Solaris 9 and 10, and OpenSolaris before snv100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0267?
CVE-2009-0267 is classified as a moderate severity vulnerability due to its potential to cause a denial of service by crashing the in.iked daemon.
How do I fix CVE-2009-0267?
To fix CVE-2009-0267, upgrade to a patched version of the affected software as provided by the vendor.
Which Solaris versions are affected by CVE-2009-0267?
CVE-2009-0267 affects multiple versions of Sun Solaris 9, Solaris 10, and OpenSolaris prior to snv_100.
What type of vulnerability is CVE-2009-0267?
CVE-2009-0267 is classified as a denial of service vulnerability that impacts the IKE packet processing.
Who can exploit CVE-2009-0267?
Remote attackers can exploit CVE-2009-0267 by sending specially crafted IKE packets to vulnerable systems.