Vulnerability Description
src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which allows remote attackers to cause a denial of service (resource consumption).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ipsec-Tools | Ipsec-Tools | All versions |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
- http://secunia.com/advisories/31478
- http://secunia.com/advisories/31624
- http://secunia.com/advisories/32759
- http://secunia.com/advisories/32971
- http://secunia.com/advisories/35074
- http://security.gentoo.org/glsa/glsa-200812-03.xml
- http://sourceforge.net/mailarchive/forum.php?thread_name=48a0c7a0.qPeWZAE0PY8bDD
- http://support.apple.com/kb/HT3549
- http://support.apple.com/kb/HT3639
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:181
- http://www.redhat.com/support/errata/RHSA-2008-0849.html
FAQ
What is CVE-2008-3652?
CVE-2008-3652 is a vulnerability with a CVSS score of 7.8 (HIGH). src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which allows remote attackers to cause a denial of service (resour...
How severe is CVE-2008-3652?
CVE-2008-3652 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3652?
Check the references section above for vendor advisories and patch information. Affected products include: Ipsec-Tools Ipsec-Tools.