Candidate: CVE-2009-1574 PublicDate: 2009-05-06 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1574 https://ubuntu.com/security/notices/USN-785-1 Description: racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: Patches_ipsec-tools: upstream: http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/isakmp_frag.c.diff?r1=1.4&r2=1.4.6.1&f=h upstream_ipsec-tools: released (1:0.7.1-1.4, 0.7.2) dapper_ipsec-tools: released (1:0.6.5-4ubuntu1.3) hardy_ipsec-tools: released (1:0.6.7-1.1ubuntu1.2) intrepid_ipsec-tools: released (1:0.7-2.1ubuntu1.8.10.1) jaunty_ipsec-tools: released (1:0.7-2.1ubuntu1.9.04.1) devel_ipsec-tools: released (0.7.1-1.5ubuntu1)