Denial of Service Vulnerability in Openswan and Strongswan IPsec Daemons
CVE-2009-0790
Currently unrated
What is CVE-2009-0790?
The Pluto IKE daemon in Openswan and Strongswan IPsec allows remote attackers to induce a denial of service by sending malformed Dead Peer Detection (DPD) IPsec IKE notification messages. This action can cause a crash and subsequent restart of the daemon, resulting from a NULL pointer dereference tied to inconsistent ISAKMP state and the absence of a phase2 state association during DPD processing.
