CVE-2009-1958: Medium severity strongSwan Strongswan vulnerability
charon/sa/tasks/childcreate.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKEAUTH request without a (1) TSi or (2) TSr traffic selector.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1958?
CVE-2009-1958 has the potential to cause a denial of service, which impacts availability.
How do I fix CVE-2009-1958?
To fix CVE-2009-1958, upgrade to strongSwan version 4.3.1 or later.
Which versions of strongSwan are affected by CVE-2009-1958?
CVE-2009-1958 affects multiple versions of strongSwan prior to 4.3.1 including several versions from 2.0.0 to 4.2.9.
What kind of attacks can exploit CVE-2009-1958?
CVE-2009-1958 can be exploited by sending IKE_AUTH requests without proper traffic selectors, causing a denial of service.
Is there any workaround for CVE-2009-1958?
There is no known workaround for CVE-2009-1958 other than updating to a patched version of strongSwan.