Vulnerability Bulletins

DSA-3272 ipsec-tools - security update


System information

   
Affected software Debian

Description

Javantea discovered a NULL pointer dereference flaw in racoon, theInternet Key Exchange daemon of ipsec-tools. A remote attacker can usethis flaw to cause the IKE daemon to crash via specially crafted UDPpackets, resulting in a denial of service.

More info:

https://www.debian.org/security/2015/dsa-3272

Standar resources

Property Value
CVE CVE-2015-4047 and DSA-3272.

Version history

Version Comments Date
1.0 Advisory issued 2015-05-25
Ministerio de Defensa
CNI
CCN
CCN-CERT