OpenBSD ISAKMPD Security Association Piggyback Delete Payload Denial Of Service Vulnerability
BID:10496
Info
OpenBSD ISAKMPD Security Association Piggyback Delete Payload Denial Of Service Vulnerability
| Bugtraq ID: | 10496 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2004 12:00AM |
| Updated: | Jun 08 2004 12:00AM |
| Credit: | Thomas Walpuski <[email protected]> disclosed this vulnerability to Bugtraq. |
| Vulnerable: |
OpenBSD OpenBSD 3.5 OpenBSD OpenBSD 3.4 OpenBSD OpenBSD 3.3 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 OpenBSD OpenBSD -current |
| Not Vulnerable: | |
Discussion
OpenBSD ISAKMPD Security Association Piggyback Delete Payload Denial Of Service Vulnerability
It is reported that OpenBSD's isakmpd daemon is susceptible to a remote denial of service vulnerability.
An attacker is able to delete security associations and policies from IPSec VPN's by sending a malformed UDP ISAKMP packet to a vulnerable server. The malformed packet contains payloads for both setting up a new tunnel and deleting a tunnel. Isakmpd improperly acts upon the delete payload and terminates the associations and policys relating to the tunnel.
It is possible to destroy security associations, effectively eliminating the VPN connection between gateways, denying service to legitimate users of the VPN.
It is reported that OpenBSD's isakmpd daemon is susceptible to a remote denial of service vulnerability.
An attacker is able to delete security associations and policies from IPSec VPN's by sending a malformed UDP ISAKMP packet to a vulnerable server. The malformed packet contains payloads for both setting up a new tunnel and deleting a tunnel. Isakmpd improperly acts upon the delete payload and terminates the associations and policys relating to the tunnel.
It is possible to destroy security associations, effectively eliminating the VPN connection between gateways, denying service to legitimate users of the VPN.
Exploit / POC
OpenBSD ISAKMPD Security Association Piggyback Delete Payload Denial Of Service Vulnerability
Proof of concept code was released by Thomas Walpuski <[email protected]>
Proof of concept code was released by Thomas Walpuski <[email protected]>
Solution / Fix
OpenBSD ISAKMPD Security Association Piggyback Delete Payload Denial Of Service Vulnerability
Solution:
OpenBSD has committed a change in CVS which partially fixes this issue. Please see the referenced web pages for a patch for OpenBSD-current.
Further information will be added when an official OpenBSD response is released.
Update: As of 10 June, 2004 patches are available that address this issue. Please see the referenced fixes for information on application of these patches.
OpenBSD OpenBSD 3.5
Solution:
OpenBSD has committed a change in CVS which partially fixes this issue. Please see the referenced web pages for a patch for OpenBSD-current.
Further information will be added when an official OpenBSD response is released.
Update: As of 10 June, 2004 patches are available that address this issue. Please see the referenced fixes for information on application of these patches.
OpenBSD OpenBSD 3.5
-
OpenBSD 012_isakmpd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/012_isakmpd.patch
References
OpenBSD ISAKMPD Security Association Piggyback Delete Payload Denial Of Service Vulnerability
References:
References:
- OpenBSD Errata Page (OpenBSD)
- OpenBSD Homepage (OpenBSD)
- Re: unauthorized deletion of IPsec SAs in isakmpd, still (Thomas Walpuski
) - unauthorized deletion of IPsec SAs in isakmpd, still (Thomas Walpuski
)