Lucene search

K
ubuntuUbuntuUSN-107-1
HistoryApr 06, 2005 - 12:00 a.m.

racoon vulnerability

2005-04-0600:00:00
ubuntu.com
37

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.9 Medium

AI Score

Confidence

Low

0.039 Low

EPSS

Percentile

92.0%

Releases

  • Ubuntu 4.10

Details

Sebastian Krahmer discovered a Denial of Service vulnerability in the
racoon daemon. By sending specially crafted ISAKMP packets, a remote
attacker could trigger a buffer overflow which caused racoon to crash.

This update does not introduce any source code changes affecting the
ipsec-tools package. It is necessary to update the version number of
the package in order to support an update to the “racoon” package.
Please note that racoon is not officially supported by Ubuntu (it is
in the “universe” component of the archive).

OSVersionArchitecturePackageVersionFilename
Ubuntu4.10noarchracoon< *UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.9 Medium

AI Score

Confidence

Low

0.039 Low

EPSS

Percentile

92.0%