Back to Database
Status published
High
CVE-2015-4047
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a...
Vulnerability Description
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-4047
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.debian.org/security/2015/dsa-3272
- http://seclists.org/fulldisclosure/2015/May/83
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159482.html
- http://seclists.org/fulldisclosure/2015/May/81
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159549.html
- https://www.altsci.com/ipsec/ipsec-tools-sa.html
- http://www.securitytracker.com/id/1032397
- http://www.openwall.com/lists/oss-security/2015/05/20/1
- http://www.securityfocus.com/bid/74739
- http://packetstormsecurity.com/files/131992/IPsec-Tools-0.8.2-Denial-Of-Service.html
- http://www.ubuntu.com/usn/USN-2623-1
- http://www.openwall.com/lists/oss-security/2015/05/21/11
- https://support.f5.com/csp/article/K05013313
More from ipsec-tools
View All →CVE-2016-10396
The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable...
High
7.5
CVE-2009-1632
Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers...
Medium
5
CVE-2009-1574
racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause...
Medium
5
CVE-2008-3652
src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned...
High
7.8
CVE-2007-1841
The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before...
Medium
4.3
Affected Vendor
ipsec-tools
View all reports →Affected Software
ipsec-tools, ubuntu linux, fedora, big-ip application acceleration manager, big-ip local traffic manager, big-ip advanced firewall manager, big-ip analytics, big-ip access policy manager, big-ip application security manager, big-ip domain name system, big-ip edge gateway, big-ip global traffic manager, big-ip link controller, big-ip policy enforcement manager, big-ip protocol security manager, big-ip wan optimization manager, big-ip webaccelerator, big-iq adc, big-iq centralized management, big-iq cloud, big-iq cloud and orchestration, big-iq device, big-iq security, enterprise manager, debian linux
Vulnerable Versions:
0.8.2, 12.04, 20, 21, 11.4.0, 12.0.0, 13.0.0, 11.0.0, 11.3.0, 4.5.0, 4.6.0, 4.0.0, 1.0.0, 4.2.0, 3.0.0, 7.0, 8.0, 9.0
Timeline
Official Publish:
May 29th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.