>> IPsec Tools "isakmp_info_recv()" Packets Handling Denial of Service Vulnerability
Title : IPsec Tools "isakmp_info_recv()" Packets Handling Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-1310 CVE ID : CVE-2007-1841
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-10
Technical Description
A vulnerability has been identified in IPsec-tools, which could be exploited by attackers to cause a denial of service. This issue is caused by an error in the IPSec key exchange server "racoon" that fails to properly validate certain requests via the "isakmp_info_recv()" [src/racoon/isakmp_inf.c] function, which could be exploited by attackers to disrupt established IPSec tunnels and create a denial of service condition by sending specially crafted packets.