KAME Racoon Remote IKE Message Denial Of Service Vulnerability
BID:10296
Info
KAME Racoon Remote IKE Message Denial Of Service Vulnerability
| Bugtraq ID: | 10296 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0392 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery of this issue is credited to John Lampe <[email protected]>. |
| Vulnerable: |
SCO Unixware 7.1.4 KAME Racoon 20040405 KAME Racoon 20030711 KAME Racoon |
| Not Vulnerable: |
KAME Racoon 20040503 KAME Racoon 20040407b |
Discussion
KAME Racoon Remote IKE Message Denial Of Service Vulnerability
It has been reported that KAME is affected by a remote denial of service vulnerability when processing malformed IKE messages. This issue is due to a failure of the daemon to properly handle malformed messages.
This issue can be leveraged to cause the affected daemon to enter an infinite loop; effectively denying service to legitimate users.
It has been reported that KAME is affected by a remote denial of service vulnerability when processing malformed IKE messages. This issue is due to a failure of the daemon to properly handle malformed messages.
This issue can be leveraged to cause the affected daemon to enter an infinite loop; effectively denying service to legitimate users.
Exploit / POC
KAME Racoon Remote IKE Message Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
KAME Racoon Remote IKE Message Denial Of Service Vulnerability
Solution:
The KAME project has released updates dealing with this issue.
SCO has released advisory SCOSA-2005.10 to address various issues in Racoon affecting UnixWare 7.1.4. Please see the referenced advisory for more information.
KAME Racoon 20040405
KAME Racoon
KAME Racoon 20030711
SCO Unixware 7.1.4
Solution:
The KAME project has released updates dealing with this issue.
SCO has released advisory SCOSA-2005.10 to address various issues in Racoon affecting UnixWare 7.1.4. Please see the referenced advisory for more information.
KAME Racoon 20040405
-
KAME kame-20040503-openbsd34-snap.tgz
ftp://ftp.kame.net/pub/kame/snap/kame-20040503-openbsd34-snap.tgz
KAME Racoon
-
KAME kame-20040503-openbsd34-snap.tgz
ftp://ftp.kame.net/pub/kame/snap/kame-20040503-openbsd34-snap.tgz
KAME Racoon 20030711
-
KAME kame-20040503-openbsd34-snap.tgz
ftp://ftp.kame.net/pub/kame/snap/kame-20040503-openbsd34-snap.tgz
SCO Unixware 7.1.4
-
SCO erg712650.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/erg712650.pkg.Z
References
KAME Racoon Remote IKE Message Denial Of Service Vulnerability
References:
References:
- Problem Report fbsd4/555 (KAME Project)
- Vendor Homepage (KAME Project)