CVE-2008-4551

strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NULL values in a Key Exchange payload, which triggers a NULL pointer dereference for the return value of the mpz_export function in the GNU Multiprecision Library (GMP).
Configurations

Configuration 1

cpe:2.3:a:strongswan:strongswan:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.8:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.11:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.10:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.0a:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.9:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.2:*:*:*:*:*:*:*

Information

Published : 2008-10-14 08:00

Updated : 2011-03-08 03:12


NVD link : CVE-2008-4551

Mitre link : CVE-2008-4551

Products Affected
No products.
CWE