>> IPsec-Tools Invalid Proposals Denial of Service Vulnerability
Title : IPsec-Tools Invalid Proposals Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2345 CVE ID : CVE-2008-3651 CWE ID : CWE-400
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-12
Technical Description
A vulnerability has been identified in IPsec-Tools, which could be exploited by remote attackers to cause a denial of service. This issue is caused by a memory leak when receiving invalid proposals, which could be exploited by attackers to create a denial of service condition.