CVE-2009-0790
Last modified
CVE-2009-0790 is a vulnerability of currently unknown severity. The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.. EPSS estimates a 3.18% chance of exploitation in the next 30 days.
Description
The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Strongswan | Strongswan | 2.4.0 |
| Strongswan | Strongswan | 2.4.0a |
| Strongswan | Strongswan | 2.4.1 |
| Strongswan | Strongswan | 2.4.2 |
| Strongswan | Strongswan | 2.4.3 |
| Strongswan | Strongswan | 2.4.4 |
| Strongswan | Strongswan | 2.6.0 |
| Strongswan | Strongswan | 2.6.1 |
| Strongswan | Strongswan | 2.6.2 |
| Strongswan | Strongswan | 2.6.3 |
| Strongswan | Strongswan | 2.6.4 |
| Strongswan | Strongswan | 2.8.0 |
| Strongswan | Strongswan | 2.8.1 |
| Strongswan | Strongswan | 2.8.2 |
| Strongswan | Strongswan | 2.8.3 |
| Strongswan | Strongswan | 2.8.4 |
| Strongswan | Strongswan | 2.8.5 |
| Strongswan | Strongswan | 2.8.6 |
| Strongswan | Strongswan | 2.8.7 |
| Strongswan | Strongswan | 2.8.8 |
| Strongswan | Strongswan | 4.2.0 |
| Strongswan | Strongswan | 4.2.1 |
| Strongswan | Strongswan | 4.2.2 |
| Strongswan | Strongswan | 4.2.3 |
| Strongswan | Strongswan | 4.2.4 |
| Strongswan | Strongswan | 4.2.5 |
| Strongswan | Strongswan | 4.2.6 |
| Strongswan | Strongswan | 4.2.7 |
| Strongswan | Strongswan | 4.2.8 |
| Strongswan | Strongswan | 4.2.9 |
| Strongswan | Strongswan | 4.2.10 |
| Strongswan | Strongswan | 4.2.11 |
| Strongswan | Strongswan | 4.2.12 |
| Strongswan | Strongswan | 4.2.13 |
| Xelerance | Openswan | 2.4.0 |
| Xelerance | Openswan | 2.4.1 |
| Xelerance | Openswan | 2.4.2 |
| Xelerance | Openswan | 2.4.3 |
| Xelerance | Openswan | 2.4.4 |
| Xelerance | Openswan | 2.4.5 |
| Xelerance | Openswan | 2.4.9 |
| Xelerance | Openswan | 2.4.10 |
| Xelerance | Openswan | 2.6.03 |
| Xelerance | Openswan | 2.6.04 |
| Xelerance | Openswan | 2.6.05 |
| Xelerance | Openswan | 2.6.06 |
| Xelerance | Openswan | 2.6.07 |
| Xelerance | Openswan | 2.6.08 |
| Xelerance | Openswan | 2.6.09 |
| Xelerance | Openswan | 2.6.10 |
Showing 50 of 60 affected configurations. See NVD for the full list.
References
- http://download.strongswan.org/CHANGES4.txtVendor Advisory
- http://secunia.com/advisories/34472Vendor Advisory
- http://secunia.com/advisories/34483Vendor Advisory
- http://secunia.com/advisories/34494Vendor Advisory
- http://secunia.com/advisories/34546Vendor Advisory
- http://www.openswan.org/CVE-2009-0790/CVE-2009-0790.txtVendor Advisory
- http://download.strongswan.org/CHANGES4.txtVendor Advisory
- http://secunia.com/advisories/34472Vendor Advisory
- http://secunia.com/advisories/34483Vendor Advisory
- http://secunia.com/advisories/34494Vendor Advisory
- http://secunia.com/advisories/34546Vendor Advisory
- http://www.openswan.org/CVE-2009-0790/CVE-2009-0790.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0790?
How severe is CVE-2009-0790?
How do I fix CVE-2009-0790?
Are you affected by CVE-2009-0790?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
