CVE-2009-1574: Null Pointer Dereference
ipsec-tools upstream version 0.7.2 announcement mentions following security fix:
o Fix a remote crash in fragmentation code
http://sourceforge.net/project/shownotes.php?groupid=74601&releaseid=677611
Upstream CVS commit provides further details:
From Neil Kettle: Fix a possible null pointer dereference in fragmentation code.
http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/isakmpfrag.c?f=h#rev1.4.6.1 http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/isakmpfrag.c.diff?r1=1.4&r2=1.4.6.1&f=h
Other sources
racoon/isakmpfrag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1574?
CVE-2009-1574 has a severity level that is categorized as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2009-1574?
To fix CVE-2009-1574, update ipsec-tools to version 0.7.2 or higher.
What systems are affected by CVE-2009-1574?
CVE-2009-1574 affects various versions of ipsec-tools prior to 0.7.2, including 0.2.4 and 0.6.5.
What type of vulnerability is CVE-2009-1574?
CVE-2009-1574 is a denial of service vulnerability that can be exploited via crafted fragmented packets.
Is there a workaround for CVE-2009-1574?
A recommended workaround for CVE-2009-1574 is to implement firewall rules that drop unknown or malformed packets until a fix is applied.