Openswan IKE Traffic Denial Of Service Vulnerabilities

BID:15416

Info

Openswan IKE Traffic Denial Of Service Vulnerabilities

Bugtraq ID: 15416
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2005-3671
Remote: Yes
Local: No
Published: Nov 14 2005 12:00AM
Updated: May 10 2006 02:59AM
Credit: Discovery is credited to the vendor.
Vulnerable: SuSE Linux Enterprise Server 9
S.u.S.E. Linux Professional 10.0 OSS
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Personal 10.0 OSS
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
Redhat Fedora Core4
Redhat Fedora Core3
Openswan Openswan 2.4
Openswan Openswan 2.3.1
Openswan Openswan 2.3
Openswan Openswan 2.2
Openswan Openswan 2.1.6
Openswan Openswan 2.1.5
+ Redhat Fedora Core3
Openswan Openswan 2.1.4
Openswan Openswan 2.1.2
Openswan Openswan 2.1.1
Gentoo Linux
Astaro Security Linux 4.0 28
Not Vulnerable: Openswan Openswan 2.4.4
Openswan Openswan 2.4.2
Astaro Security Linux 4.0 29

Discussion

Openswan IKE Traffic Denial Of Service Vulnerabilities

Openswan is prone to multiple denial-of-service vulnerabilities in their ISAKMP implementation. Only attackers with access to the pre-shared key may exploit these issues, and only when the affected IKE daemon is configured to use aggressive mode.

These issues were discovered with the PROTOS ISAKMP Test Suite and are related to the handling of malformed IKEv1 traffic.

The vulnerabilities are believed to affect Openswan 2.x releases prior to 2.4.2.

Exploit / POC

Openswan IKE Traffic Denial Of Service Vulnerabilities

These issues can be reproduced using the PROTOS ISAKMP Test Suite.

Solution / Fix

Openswan IKE Traffic Denial Of Service Vulnerabilities

Solution:

The vendor has released Openswan 2.4.2 to address the issues.

Please see the referenced advisories for further information.


Openswan Openswan 2.1.1

Openswan Openswan 2.1.2

Openswan Openswan 2.1.4

Openswan Openswan 2.1.5

Openswan Openswan 2.1.6

Openswan Openswan 2.2

Openswan Openswan 2.3

Openswan Openswan 2.3.1

Openswan Openswan 2.4

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report