Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Ipsec | — | Apply OS X security update 2009-006Upgrade macOS to the latest version | Dec 16, 2011 | May 14, 2009 |
| Centos_linux | — | Upgrade ipsec-tools | Dec 1, 2016 | May 14, 2009 |
| Gentoo Linux | — | Upgrade net-firewall/ipsec-tools. | Oct 30, 2017 | May 14, 2009 |
| Oracle_linux | — | Upgrade ipsec-tools | Oct 16, 2024 | May 14, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 22, 2009 |
| Suse | — | Upgrade novell-ipsec-tools-develUpgrade novell-ipsec-toolsUpgrade ipsec-tools | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade racoon | Nov 8, 2024 | May 14, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub