Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
http://www.securitytracker.com/alerts/2004/Mar/1009468.html | vdb entry third party advisory broken link |
http://www.openbsd.org/errata.html | vendor advisory product |
http://marc.info/?l=bugtraq&m=108008530028019&w=2 | third party advisory mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15519 | vdb entry third party advisory |
http://www.securityfocus.com/bid/10032 | vdb entry third party advisory broken link |
http://www.rapid7.com/advisories/R7-0018.html | broken link |
http://www.kb.cert.org/vuls/id/996177 | third party advisory us government resource |