VulnerabilityModified
CVE-2015-4047
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
HIGH 7.8EPSS 9.81%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 9.81% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- ipsec-tools/ipsec-tools · canonical/ubuntu linux · fedoraproject/fedora · f5/big-ip application acceleration manager · f5/big-ip local traffic manager · f5/big-ip advanced firewall manager · f5/big-ip analytics · f5/big-ip access policy manager · f5/big-ip application security manager · f5/big-ip domain name system · f5/big-ip edge gateway · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip policy enforcement manager · f5/big-ip protocol security manager · f5/big-ip wan optimization manager · f5/big-ip webaccelerator · f5/big-iq adc · f5/big-iq centralized management · f5/big-iq cloud · +5 more
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159482.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159549.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/131992/IPsec-Tools-0.8.2-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/May/81Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2015/May/83Exploit, Mailing List, Third Party Advisory
- http://www.debian.org/security/2015/dsa-3272Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/05/20/1Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/05/21/11Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74739Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032397Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2623-1Third Party Advisory
- https://support.f5.com/csp/article/K05013313Third Party Advisory
- https://www.altsci.com/ipsec/ipsec-tools-sa.htmlExploit, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159482.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159549.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/131992/IPsec-Tools-0.8.2-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/May/81Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2015/May/83Exploit, Mailing List, Third Party Advisory
- http://www.debian.org/security/2015/dsa-3272Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/05/20/1Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/05/21/11Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74739Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032397Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2623-1Third Party Advisory
- https://support.f5.com/csp/article/K05013313Third Party Advisory
- https://www.altsci.com/ipsec/ipsec-tools-sa.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.