CVE-2009-0267Improper Input Validation in Opensolaris

Severity
5.0MEDIUMNVD
CNA7.8
EPSS
1.7%
top 17.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateMay 2

Description

libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDsun/opensolarissnv_99+98
NVDsun/solaris10, 9+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9r95-m9j5-g98p: libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of se2022-05-02
CVEList
CVE-2009-0267: libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of se2009-01-26
CVE-2009-0267 — Improper Input Validation | cvebase