Cisco VPN Client Zero Length IKE Packet Denial Of Service Vulnerability
BID:5440
Info
Cisco VPN Client Zero Length IKE Packet Denial Of Service Vulnerability
| Bugtraq ID: | 5440 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2002 12:00AM |
| Updated: | Aug 12 2002 12:00AM |
| Credit: | Published in a Cisco Security Advisory. CERT/CC credits Anton Rager of Avaya Communications with discovery. |
| Vulnerable: |
Cisco VPN Client for Windows 3.5.1 Cisco VPN Client for Solaris 3.5.2 Cisco VPN Client for Solaris 3.5.1 Cisco VPN Client for Mac OS X 3.5.2 Cisco VPN Client for Mac OS X 3.5.1 Cisco VPN Client for Linux 3.5.2 Cisco VPN Client for Linux 3.5.1 |
| Not Vulnerable: |
Cisco VPN Client for Windows 3.6 Cisco VPN Client for Solaris 3.6 Cisco VPN Client for Mac OS X 3.6 Cisco VPN Client for Linux 3.6 |
Discussion
Cisco VPN Client Zero Length IKE Packet Denial Of Service Vulnerability
The Cisco VPN Client is Virtual Private Network software. Some versions of the VPN Client are vulnerable to a denial of service attack.
When vulnerable clients receive a specific IKE packet with a zero length payload, the VPN client will consume all available processor time. This may result in a denial of service condition, and require that the VPN client process be manually killed and restarted in order to regain normal functionality.
The Cisco VPN Client is Virtual Private Network software. Some versions of the VPN Client are vulnerable to a denial of service attack.
When vulnerable clients receive a specific IKE packet with a zero length payload, the VPN client will consume all available processor time. This may result in a denial of service condition, and require that the VPN client process be manually killed and restarted in order to regain normal functionality.
Exploit / POC
Cisco VPN Client Zero Length IKE Packet Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco VPN Client Zero Length IKE Packet Denial Of Service Vulnerability
Solution:
This vulnerability has been fixed in Cisco VPN Client version 3.6. Fixes for this issue will be integrated into VPN Client version 3.5.4 or later, which is reported to be available for download by September 30, 2002. Customers may obtain upgrades through their regular channels, such as the Cisco's Software Center:
http://www.cisco.com/kobayashi/sw-center/
Solution:
This vulnerability has been fixed in Cisco VPN Client version 3.6. Fixes for this issue will be integrated into VPN Client version 3.5.4 or later, which is reported to be available for download by September 30, 2002. Customers may obtain upgrades through their regular channels, such as the Cisco's Software Center:
http://www.cisco.com/kobayashi/sw-center/
References
Cisco VPN Client Zero Length IKE Packet Denial Of Service Vulnerability
References:
References:
- Vulnerability Note VU#287771 (CERT/CC)