CVE Vulnerabilities

CVE-2008-4551

Published: Oct 14, 2008 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NULL values in a Key Exchange payload, which triggers a NULL pointer dereference for the return value of the mpz_export function in the GNU Multiprecision Library (GMP).

Affected Software

Name Vendor Start Version End Version
Strongswan Strongswan * 4.2.6 (including)
Strongswan Strongswan 2.0.0 (including) 2.0.0 (including)
Strongswan Strongswan 2.0.1 (including) 2.0.1 (including)
Strongswan Strongswan 2.0.2 (including) 2.0.2 (including)
Strongswan Strongswan 2.1.0 (including) 2.1.0 (including)
Strongswan Strongswan 2.1.1 (including) 2.1.1 (including)
Strongswan Strongswan 2.1.2 (including) 2.1.2 (including)
Strongswan Strongswan 2.1.3 (including) 2.1.3 (including)
Strongswan Strongswan 2.1.4 (including) 2.1.4 (including)
Strongswan Strongswan 2.1.5 (including) 2.1.5 (including)
Strongswan Strongswan 2.2.0 (including) 2.2.0 (including)
Strongswan Strongswan 2.2.1 (including) 2.2.1 (including)
Strongswan Strongswan 2.2.2 (including) 2.2.2 (including)
Strongswan Strongswan 2.3.0 (including) 2.3.0 (including)
Strongswan Strongswan 2.3.1 (including) 2.3.1 (including)
Strongswan Strongswan 2.3.2 (including) 2.3.2 (including)
Strongswan Strongswan 2.4.0 (including) 2.4.0 (including)
Strongswan Strongswan 2.4.0a (including) 2.4.0a (including)
Strongswan Strongswan 2.4.1 (including) 2.4.1 (including)
Strongswan Strongswan 2.4.2 (including) 2.4.2 (including)
Strongswan Strongswan 2.4.3 (including) 2.4.3 (including)
Strongswan Strongswan 2.5.0 (including) 2.5.0 (including)
Strongswan Strongswan 2.5.1 (including) 2.5.1 (including)
Strongswan Strongswan 2.5.2 (including) 2.5.2 (including)
Strongswan Strongswan 2.5.3 (including) 2.5.3 (including)
Strongswan Strongswan 2.5.4 (including) 2.5.4 (including)
Strongswan Strongswan 2.5.5 (including) 2.5.5 (including)
Strongswan Strongswan 2.5.6 (including) 2.5.6 (including)
Strongswan Strongswan 2.5.7 (including) 2.5.7 (including)
Strongswan Strongswan 2.6.0 (including) 2.6.0 (including)
Strongswan Strongswan 2.6.1 (including) 2.6.1 (including)
Strongswan Strongswan 2.6.2 (including) 2.6.2 (including)
Strongswan Strongswan 2.6.3 (including) 2.6.3 (including)
Strongswan Strongswan 2.6.4 (including) 2.6.4 (including)
Strongswan Strongswan 2.7.0 (including) 2.7.0 (including)
Strongswan Strongswan 4.0.0 (including) 4.0.0 (including)
Strongswan Strongswan 4.0.1 (including) 4.0.1 (including)
Strongswan Strongswan 4.0.2 (including) 4.0.2 (including)
Strongswan Strongswan 4.0.3 (including) 4.0.3 (including)
Strongswan Strongswan 4.0.4 (including) 4.0.4 (including)
Strongswan Strongswan 4.0.5 (including) 4.0.5 (including)
Strongswan Strongswan 4.0.6 (including) 4.0.6 (including)
Strongswan Strongswan 4.0.7 (including) 4.0.7 (including)
Strongswan Strongswan 4.1.0 (including) 4.1.0 (including)
Strongswan Strongswan 4.1.1 (including) 4.1.1 (including)
Strongswan Strongswan 4.1.2 (including) 4.1.2 (including)
Strongswan Strongswan 4.1.3 (including) 4.1.3 (including)
Strongswan Strongswan 4.1.4 (including) 4.1.4 (including)
Strongswan Strongswan 4.1.5 (including) 4.1.5 (including)
Strongswan Strongswan 4.1.6 (including) 4.1.6 (including)
Strongswan Strongswan 4.1.7 (including) 4.1.7 (including)
Strongswan Strongswan 4.1.8 (including) 4.1.8 (including)
Strongswan Strongswan 4.1.9 (including) 4.1.9 (including)
Strongswan Strongswan 4.1.10 (including) 4.1.10 (including)
Strongswan Strongswan 4.1.11 (including) 4.1.11 (including)
Strongswan Strongswan 4.2.0 (including) 4.2.0 (including)
Strongswan Strongswan 4.2.1 (including) 4.2.1 (including)
Strongswan Strongswan 4.2.2 (including) 4.2.2 (including)
Strongswan Strongswan 4.2.3 (including) 4.2.3 (including)
Strongswan Strongswan 4.2.4 (including) 4.2.4 (including)
Strongswan Strongswan 4.2.5 (including) 4.2.5 (including)

References