CVE-2007-1841

7 documents6 sources
Severity
4.3MEDIUM
EPSS
9.5%
top 7.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 10
Latest updateMay 1

Description

The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3c6r-mxqj-c794: The isakmp_info_recv function in src/racoon/isakmp_inf2022-05-01
CVEList
CVE-2007-1841: The isakmp_info_recv function in src/racoon/isakmp_inf2007-04-10

📋Vendor Advisories

2
Ubuntu
ipsec-tools vulnerability2007-04-09
Red Hat
ipsec-tools racoon DoS2007-04-06

💬Community

2
Bugzilla
CVE-2007-1841 ipsec-tools racoon DoS2007-04-26
Bugzilla
CVE-2007-1841 ipsec-tools racoon DoS2007-04-05