Lucene search

K
freebsdFreeBSD974A6D32-3FDA-11E8-AEA4-001B216D295B
HistoryDec 02, 2016 - 12:00 a.m.

ipsec-tools -- remotely exploitable computational-complexity attack

2016-12-0200:00:00
vuxml.freebsd.org
14

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

65.7%

Robert Foggia via NetBSD GNATS reports:

The ipsec-tools racoon daemon contains a remotely exploitable computational
complexity attack when parsing and storing isakmp fragments. The implementation
permits a remote attacker to exhaust computational resources on the remote endpoint
by repeatedly sending isakmp fragment packets in a particular order such that
the worst-case computational complexity is realized in the algorithm utilized
to determine if reassembly of the fragments can take place.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchipsec-tools< 0.8.2_3UNKNOWN

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

65.7%