5

CVE-2009-1958

charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.

Data is provided by the National Vulnerability Database (NVD)
StrongswanStrongswan Version <= 4.2.9
StrongswanStrongswan Version2.0.0
StrongswanStrongswan Version2.0.1
StrongswanStrongswan Version2.0.2
StrongswanStrongswan Version2.1.0
StrongswanStrongswan Version2.1.1
StrongswanStrongswan Version2.1.2
StrongswanStrongswan Version2.1.3
StrongswanStrongswan Version2.1.4
StrongswanStrongswan Version2.1.5
StrongswanStrongswan Version2.2.0
StrongswanStrongswan Version2.2.1
StrongswanStrongswan Version2.2.2
StrongswanStrongswan Version2.3.0
StrongswanStrongswan Version2.3.1
StrongswanStrongswan Version2.3.2
StrongswanStrongswan Version2.4.0
StrongswanStrongswan Version2.4.0a
StrongswanStrongswan Version2.4.1
StrongswanStrongswan Version2.4.2
StrongswanStrongswan Version2.4.3
StrongswanStrongswan Version2.4.4
StrongswanStrongswan Version2.5.0
StrongswanStrongswan Version2.5.1
StrongswanStrongswan Version2.5.2
StrongswanStrongswan Version2.5.3
StrongswanStrongswan Version2.5.4
StrongswanStrongswan Version2.5.5
StrongswanStrongswan Version2.5.6
StrongswanStrongswan Version2.5.7
StrongswanStrongswan Version2.6.0
StrongswanStrongswan Version2.6.1
StrongswanStrongswan Version2.6.2
StrongswanStrongswan Version2.6.3
StrongswanStrongswan Version2.6.4
StrongswanStrongswan Version2.6.16
StrongswanStrongswan Version2.6.20
StrongswanStrongswan Version2.7.0
StrongswanStrongswan Version2.8.0
StrongswanStrongswan Version2.8.1
StrongswanStrongswan Version2.8.2
StrongswanStrongswan Version2.8.3
StrongswanStrongswan Version2.8.4
StrongswanStrongswan Version2.8.5
StrongswanStrongswan Version2.8.6
StrongswanStrongswan Version2.8.7
StrongswanStrongswan Version2.8.8
StrongswanStrongswan Version4.0.0
StrongswanStrongswan Version4.0.1
StrongswanStrongswan Version4.0.2
StrongswanStrongswan Version4.0.3
StrongswanStrongswan Version4.0.4
StrongswanStrongswan Version4.0.5
StrongswanStrongswan Version4.0.6
StrongswanStrongswan Version4.0.7
StrongswanStrongswan Version4.1.0
StrongswanStrongswan Version4.1.1
StrongswanStrongswan Version4.1.2
StrongswanStrongswan Version4.1.3
StrongswanStrongswan Version4.1.4
StrongswanStrongswan Version4.1.5
StrongswanStrongswan Version4.1.6
StrongswanStrongswan Version4.1.7
StrongswanStrongswan Version4.1.8
StrongswanStrongswan Version4.1.9
StrongswanStrongswan Version4.1.10
StrongswanStrongswan Version4.1.11
StrongswanStrongswan Version4.2.0
StrongswanStrongswan Version4.2.1
StrongswanStrongswan Version4.2.2
StrongswanStrongswan Version4.2.3
StrongswanStrongswan Version4.2.4
StrongswanStrongswan Version4.2.5
StrongswanStrongswan Version4.2.6
StrongswanStrongswan Version4.2.7
StrongswanStrongswan Version4.2.8
StrongswanStrongswan Version4.2.10
StrongswanStrongswan Version4.2.11
StrongswanStrongswan Version4.2.12
StrongswanStrongswan Version4.2.13
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.74% 0.808
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P