racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
ipsec-tools upstream version 0.7.2 announcement mentions following security fix:
o Fix a remote crash in fragmentation code
http://sourceforge.net/project/shownotes.php?groupid=74601&releaseid=677611
Upstream CVS commit provides further details:
From Neil Kettle: Fix a possible null pointer dereference in fragmentation code.
http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/isakmpfrag.c?f=h#rev1.4.6.1 http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/isakmpfrag.c.diff?r1=1.4&r2=1.4.6.1&f=h
src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which allows remote attackers to cause a denial of service (resource consumption).
ipsec-tools upstream released 0.7.1 including a fix for a memory leak in racoon daemon triggered by the invalid proposals, possibly resulting in a denial of service once daemon runs out of memory.
References: http://marc.info/?l=ipsec-tools-devel&m=121688914101709&w=2 http://bugs.gentoo.org/showbug.cgi?id=232831
Upstream patch: http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/proposal.c.diff?r1=1.15&r2=1.16&f=h http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/ChangeLog.diff?r1=1.169&r2=1.170&f=h
ipsec-tools upstream released 0.7.1 including a fix for a memory leak in racoon daemon triggered by the invalid proposals, possibly resulting in a denial of service once daemon runs out of memory.
References: http://marc.info/?l=ipsec-tools-devel&m=121688914101709&w=2 http://bugs.gentoo.org/showbug.cgi?id=232831
Upstream patch: http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/proposal.c.diff?r1=1.15&r2=1.16&f=h http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/ChangeLog.diff?r1=1.169&r2=1.170&f=h