Vulnerabilities > CVE-2009-0267 - Unspecified vulnerability in SUN Opensolaris and Solaris
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN sun
nessus
Summary
libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.
Vulnerable Configurations
Nessus
NASL family Solaris Local Security Checks NASL id SOLARIS10_140196-01.NASL description SunOS 5.10: libike.so.1 patch. Date this patch was last updated by Sun : Jan/20/09 last seen 2020-06-01 modified 2020-06-02 plugin id 107519 published 2018-03-12 reporter This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/107519 title Solaris 10 (sparc) : 140196-01 NASL family Solaris Local Security Checks NASL id SOLARIS10_140196.NASL description SunOS 5.10: libike.so.1 patch. Date this patch was last updated by Sun : Jan/20/09 last seen 2018-09-01 modified 2018-08-13 plugin id 35568 published 2009-02-02 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=35568 title Solaris 10 (sparc) : 140196-01 NASL family Solaris Local Security Checks NASL id SOLARIS9_X86_114435.NASL description SunOS 5.9_x86: IKE patch. Date this patch was last updated by Sun : Aug/09/10 last seen 2016-09-26 modified 2012-06-14 plugin id 13602 published 2004-07-12 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=13602 title Solaris 9 (x86) : 114435-16 NASL family Solaris Local Security Checks NASL id SOLARIS9_113451.NASL description SunOS 5.9: IKE patch. Date this patch was last updated by Sun : Aug/09/10 last seen 2016-09-26 modified 2012-06-14 plugin id 13538 published 2004-07-12 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=13538 title Solaris 9 (sparc) : 113451-17 NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_140414-01.NASL description SunOS 5.10_x86: libike.so.1 patch. Date this patch was last updated by Sun : Jan/20/09 last seen 2020-06-01 modified 2020-06-02 plugin id 108020 published 2018-03-12 reporter This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/108020 title Solaris 10 (x86) : 140414-01 NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_140414.NASL description SunOS 5.10_x86: libike.so.1 patch. Date this patch was last updated by Sun : Jan/20/09 last seen 2018-09-01 modified 2018-08-13 plugin id 35573 published 2009-02-02 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=35573 title Solaris 10 (x86) : 140414-01
Oval
accepted | 2009-03-09T04:00:11.155-04:00 | ||||||||||||||||
class | vulnerability | ||||||||||||||||
contributors |
| ||||||||||||||||
definition_extensions |
| ||||||||||||||||
description | libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989. | ||||||||||||||||
family | unix | ||||||||||||||||
id | oval:org.mitre.oval:def:6116 | ||||||||||||||||
status | accepted | ||||||||||||||||
submitted | 2009-01-28T11:08:21.000-05:00 | ||||||||||||||||
title | Security Vulnerability with IKE Packet Handling in Solaris libike Library may Lead to a Crash of in.iked(1M) | ||||||||||||||||
version | 35 |
References
- http://secunia.com/advisories/33702
- http://secunia.com/advisories/33702
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-113451-15-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-113451-15-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-247406-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-247406-1
- http://support.avaya.com/elmodocs2/security/ASA-2009-032.htm
- http://support.avaya.com/elmodocs2/security/ASA-2009-032.htm
- http://www.securityfocus.com/bid/33407
- http://www.securityfocus.com/bid/33407
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48178
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48178
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6116
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6116