CVE-2009-1958

charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.0a:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.5.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.16:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.6.20:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:2.8.8:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.8:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.9:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.10:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.1.11:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.6:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.7:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.8:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.10:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.11:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.12:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:4.2.13:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-06-08 01:00

Updated : 2023-12-10 10:51


NVD link : CVE-2009-1958

Mitre link : CVE-2009-1958

CVE.ORG link : CVE-2009-1958


JSON object : View

Products Affected

strongswan

  • strongswan
CWE
CWE-399

Resource Management Errors