5

CVE-2009-1957

charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.

Data is provided by the National Vulnerability Database (NVD)
StrongswanStrongswan Version <= 4.3.0
StrongswanStrongswan Version2.0.0
StrongswanStrongswan Version2.0.1
StrongswanStrongswan Version2.0.2
StrongswanStrongswan Version2.1.0
StrongswanStrongswan Version2.1.1
StrongswanStrongswan Version2.1.2
StrongswanStrongswan Version2.1.3
StrongswanStrongswan Version2.1.4
StrongswanStrongswan Version2.1.5
StrongswanStrongswan Version2.2.0
StrongswanStrongswan Version2.2.1
StrongswanStrongswan Version2.2.2
StrongswanStrongswan Version2.3.0
StrongswanStrongswan Version2.3.1
StrongswanStrongswan Version2.3.2
StrongswanStrongswan Version2.4.0
StrongswanStrongswan Version2.4.0a
StrongswanStrongswan Version2.4.1
StrongswanStrongswan Version2.4.2
StrongswanStrongswan Version2.4.3
StrongswanStrongswan Version2.4.4
StrongswanStrongswan Version2.5.0
StrongswanStrongswan Version2.5.1
StrongswanStrongswan Version2.5.2
StrongswanStrongswan Version2.5.3
StrongswanStrongswan Version2.5.4
StrongswanStrongswan Version2.5.5
StrongswanStrongswan Version2.5.6
StrongswanStrongswan Version2.5.7
StrongswanStrongswan Version2.6.0
StrongswanStrongswan Version2.6.1
StrongswanStrongswan Version2.6.2
StrongswanStrongswan Version2.6.3
StrongswanStrongswan Version2.6.4
StrongswanStrongswan Version2.6.16
StrongswanStrongswan Version2.6.20
StrongswanStrongswan Version2.7.0
StrongswanStrongswan Version2.8.0
StrongswanStrongswan Version2.8.1
StrongswanStrongswan Version2.8.2
StrongswanStrongswan Version2.8.3
StrongswanStrongswan Version2.8.4
StrongswanStrongswan Version2.8.5
StrongswanStrongswan Version2.8.6
StrongswanStrongswan Version2.8.7
StrongswanStrongswan Version2.8.8
StrongswanStrongswan Version4.0.0
StrongswanStrongswan Version4.0.1
StrongswanStrongswan Version4.0.2
StrongswanStrongswan Version4.0.3
StrongswanStrongswan Version4.0.4
StrongswanStrongswan Version4.0.5
StrongswanStrongswan Version4.0.6
StrongswanStrongswan Version4.0.7
StrongswanStrongswan Version4.1.0
StrongswanStrongswan Version4.1.1
StrongswanStrongswan Version4.1.2
StrongswanStrongswan Version4.1.3
StrongswanStrongswan Version4.1.4
StrongswanStrongswan Version4.1.5
StrongswanStrongswan Version4.1.6
StrongswanStrongswan Version4.1.7
StrongswanStrongswan Version4.1.8
StrongswanStrongswan Version4.1.9
StrongswanStrongswan Version4.1.10
StrongswanStrongswan Version4.1.11
StrongswanStrongswan Version4.2.0
StrongswanStrongswan Version4.2.1
StrongswanStrongswan Version4.2.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.74% 0.808
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P