CVE-2015-4047: Null Pointer Dereference
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4047?
CVE-2015-4047 has a high severity rating due to its potential to cause a denial of service through a NULL pointer dereference and crash of the IKE daemon.
How do I fix CVE-2015-4047?
To fix CVE-2015-4047, update your IPsec-Tools to a version later than 0.8.2 that addresses this vulnerability.
Which software is affected by CVE-2015-4047?
CVE-2015-4047 affects IPsec-Tools version 0.8.2 and several versions of F5 BIG-IP products, Ubuntu Linux 12.04, and various Debian releases.
Can CVE-2015-4047 be exploited remotely?
Yes, CVE-2015-4047 can be exploited by remote attackers through a series of crafted UDP requests.
What happens if I am affected by CVE-2015-4047?
If affected by CVE-2015-4047, your system may experience crashes of the IKE daemon, leading to service disruption.