CVE-2015-4047

Name
CVE-2015-4047
Description
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit http://seclists.org/fulldisclosure/2015/May/81
Third Party Advisory http://www.debian.org/security/2015/dsa-3272
Mailing List http://www.openwall.com/lists/oss-security/2015/05/20/1
Third Party Advisory http://www.securityfocus.com/bid/74739
Mailing List http://seclists.org/fulldisclosure/2015/May/83
Third Party Advisory http://www.securitytracker.com/id/1032397
Third Party Advisory http://packetstormsecurity.com/files/131992/IPsec-Tools-0.8.2-Denial-Of-Service.html
Mailing List http://www.openwall.com/lists/oss-security/2015/05/21/11
Exploit https://www.altsci.com/ipsec/ipsec-tools-sa.html
Third Party Advisory http://www.ubuntu.com/usn/USN-2623-1
Mailing List http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159549.html
Mailing List http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159482.html
Third Party Advisory https://support.f5.com/csp/article/K05013313

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ipsec-tools:ipsec-tools:0.8.2:*:*:*:*:*:*:* ipsec-tools == None == 0.8.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ipsec-tools 3.12-main 0.8.2-r9 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ipsec-tools 3.11-main 0.8.2-r9 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable