IKE: Openswan and Strongswan Dead Peer Detection Null Pointer Dereference Denial of Service

This signature detects attempts to exploit a known vulnerability against Openswan and Strongswan IPsec. A successful attack can result in a denial-of-service condition. This is an old issue and newer versions of the applications are unaffected by this vulnerability.

Extended Description

Openswan and strongSwan are prone to a remote denial-of-service vulnerability because they fail to properly handle certain Dead Peer Detection (DPD) packets. Attackers can exploit this issue to crash the pluto IKE daemon, denying access to legitimate users. Versions *prior to* the following are affected: Openswan 2.6.21 Openswan 2.4.14 strongSwan 4.2.14 strongSwan 2.8.9

Affected Products

Debian linux

References

BugTraq: 34296

CVE: CVE-2009-0790

Short Name
IKE:OPENSWAN-DPD-NULL-PTR-DOS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
IKE
Keywords
CVE-2009-0790 Dead Denial Dereference Detection Null Openswan Peer Pointer Service Strongswan and bid:34296 of
Release Date
03/05/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Red_hat

Suse

Gentoo

Strongswan

Debian

Openswan

CVSS Score

5.0

Found a potential security threat?