CVE-2009-1632: Medium severity Ipsec-tools Ipsec-tools vulnerability
Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eaycheckx509sign function in src/racoon/cryptoopenssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1632?
CVE-2009-1632 is classified as a denial of service vulnerability due to memory leaks.
How do I fix CVE-2009-1632?
To mitigate CVE-2009-1632, upgrade to Ipsec-tools version 0.7.2 or later.
What software versions are affected by CVE-2009-1632?
CVE-2009-1632 affects Ipsec-tools versions prior to 0.7.2.
What is the impact of CVE-2009-1632?
CVE-2009-1632 allows remote attackers to cause denial of service through memory consumption.
Who can exploit CVE-2009-1632?
Remote attackers can exploit CVE-2009-1632 through user authentication processes involving X.509 certificates.