Multiple vulnerabilities were identified in the Internet Security Association and Key Management Protocol (ISAKMP), which may be exploited by remote attackers to cause a denial of service or execute arbitrary commands. These issues are due to errors in certain ISAKMP implementations that do not properly handle IKE (Internet Key Exchange) Phase 1 packets with invalid and/or abnormal contents, which could be exploited by attackers to cause denial of service conditions or compromise vulnerable systems [...]
Solution
Use packet filters and accept ISAKMP negotiations only from trusted sources.
Credits
Vulnerabilities reported by University of Oulu Secure Programming Group (OUSPG)
ChangeLog
2005-11-14 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.