CVE-2015-4047

Published May 29, 2015

Last updated 19 days ago

Overview

Description
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
Source
cve@mitre.org
NVD status
Modified
Products
ipsec-tools, ubuntu_linux, fedora, big-ip_application_acceleration_manager, big-ip_local_traffic_manager, big-ip_advanced_firewall_manager, big-ip_analytics, big-ip_access_policy_manager, big-ip_application_security_manager, big-ip_domain_name_system, big-ip_edge_gateway, big-ip_global_traffic_manager, big-ip_link_controller, big-ip_policy_enforcement_manager, big-ip_protocol_security_manager, big-ip_wan_optimization_manager, big-ip_webaccelerator, big-iq_adc, big-iq_centralized_management, big-iq_cloud, big-iq_cloud_and_orchestration, big-iq_device, big-iq_security, enterprise_manager, debian_linux

Risk scores

CVSS 2.0

Type
Primary
Base score
7.8
Impact score
6.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:N/A:C

Weaknesses

nvd@nist.gov
CWE-476

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.