VDB
CVE-2005-3732
CVE-2005-3732
PUBLISHED
CVSS 7.800000190734863 HIGH
The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
EPSS 4.44% · 90.5th percentile
Risk Scores
CVSS 2.0
7.800000190734863
EPSS Score
4.44%
90.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ipsec-tools | ipsec-tools | 0.5.2, 0.5, 0.5.1 |
| n/a | n/a | * |
Timeline
- Nov 17, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Apr 16, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://cvs.sourceforge.net/viewcvs.py/ipsec-tools/ipsec-tools/src/racoon/isakmp_agg.c?r1=1.20.2.3&r2=1.20.2.4&diff_format=u url
- [ipsec-tools-devel] 20051120 Potential DoS fixed in ipsec-tools mailing-list
- 20051214 Re: [ GLSA 200512-04 ] Openswan, IPsec-Tools: Vulnerabilities in ISAK MP Protocol implementation mailing-list
- GLSA-200512-04 vendor-advisory
- 20060501-01-U vendor-advisory
- FLSA-2006:190941 vendor-advisory
- SUSE-SA:2005:070 vendor-advisory
- 20210 third-party-advisory
- 1015254 vdb
- RHSA-2006:0267 vendor-advisory
- 17822 third-party-advisory
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/ technical
- http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=en technical
- http://secunia.com/advisories/17668 patch
- http://secunia.com/advisories/18616 technical
- http://secunia.com/advisories/19833 advisory
- http://www.vupen.com/english/advisories/2005/2521 advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9857 technical
- https://usn.ubuntu.com/221-1/ technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-3732 advisory
…and 8 more