SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#226364

Multiple vulnerabilities in Internet Key Exchange (IKE) version 1 implementations

Overview

Numerous vulnerabilities have been reported in various Internet Key Exchange version 1 (IKEv1) implementations. The impacts of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or cause an IKEv1 implementation to behave in an unstable/unpredictable manner.

I. Description

The U.K. National Infrastructure Security Co-ordination Center (NISCC) and CERT-FI have reported numerous vulnerabilities in IKEv1 implementations. The IKE protocol (RFC 2409) operates within the framework of the Internet Security Association (SA) and Key Management Protocol (ISAKMP, RFC 2408) and provides a way for nodes to authenticate each other and exchange keying material that is used to establish secure network services. IKE is commonly used by IPSec-based VPNs. The IKE negotiation process consists of two phases. Phase 1 establishes an ISAKMP SA. Phase 2 is used to create SAs for other security protocols.

These vulnerabilities were discovered using the PROTOS Test Tool developed by Oulu University Secure Programming Group (OUSPG). The results of the tests are described in NISCC Vulnerability Advisory 273756/NISCC/ISAKMP. According to that advisory, many IKEv1 implementations contain buffer overflow, format string, and other unspecified vulnerabilities in phase 1 of IKEv1. Exploitation of these vulnerabilities may allow a remote attacker to compromise a system's security.

II. Impact

These vulnerabilities may allow a remote attacker to execute arbitrary code, cause a denial-of-service condition, gain access to sensitive information, or cause an IKEv1 implementation to behave in an unstable/unpredictable manner. In addition, many of these vulnerabilities may be exploited remotely by sending a specially crafted packet to a vulnerable IKEv1 installation.

III. Solution

Apply a patch from an affected product vendor

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown15-Nov-2005
AlcatelUnknown15-Nov-2005
Apple Computer, Inc.Unknown15-Nov-2005
AT&TUnknown15-Nov-2005
Avaya, Inc.Unknown15-Nov-2005
Avici Systems, Inc.Unknown15-Nov-2005
Borderware TechnologiesUnknown15-Nov-2005
CerticomUnknown15-Nov-2005
Charlotte's Web NetworksUnknown15-Nov-2005
Check Point Software TechnologiesVulnerable17-Nov-2005
Chiaro Networks, Inc.Unknown15-Nov-2005
Cisco Systems, Inc.Vulnerable17-Nov-2005
Computer AssociatesUnknown15-Nov-2005
Conectiva Inc.Unknown15-Nov-2005
Cray Inc.Unknown15-Nov-2005
D-Link Systems, Inc.Unknown15-Nov-2005
Data Connection, Ltd.Unknown15-Nov-2005
Debian GNU/LinuxUnknown15-Nov-2005
EMC, Inc. (formerly Data General Corporation)Unknown15-Nov-2005
Engarde Secure LinuxUnknown15-Nov-2005
EricssonUnknown15-Nov-2005
eSoft, Inc.Unknown15-Nov-2005
Extreme NetworksUnknown15-Nov-2005
F-Secure CorporationUnknown15-Nov-2005
F5 Networks, Inc.Unknown15-Nov-2005
Fedora ProjectUnknown15-Nov-2005
Force10 Networks, Inc.Unknown15-Nov-2005
Fortinet, Inc.Vulnerable12-Dec-2005
Foundry Networks, Inc.Unknown15-Nov-2005
FreeBSD, Inc.Unknown15-Nov-2005
FreeS/WanUnknown15-Nov-2005
FujitsuUnknown15-Nov-2005
Gentoo LinuxUnknown15-Nov-2005
Global Technology AssociatesUnknown15-Nov-2005
GNU netfilterUnknown15-Nov-2005
Hewlett-Packard CompanyVulnerable17-Nov-2005
HitachiNot Vulnerable3-Jan-2006
HyperchipUnknown15-Nov-2005
IBM CorporationUnknown15-Nov-2005
IBM Corporation (zseries)Unknown15-Nov-2005
IBM eServerUnknown15-Nov-2005
Immunix Communications, Inc.Unknown15-Nov-2005
Ingrian Networks, Inc.Unknown15-Nov-2005
Intel CorporationUnknown15-Nov-2005
Internet Initiative JapanUnknown15-Nov-2005
Internet Security Systems, Inc.Unknown15-Nov-2005
IntotoNot Vulnerable17-Nov-2005
IP FilterUnknown15-Nov-2005
Jun-ichiro itojun HaginoUnknown15-Nov-2005
Juniper Networks, Inc.Unknown15-Nov-2005
Linksys (A division of Cisco Systems)Unknown15-Nov-2005
Lucent TechnologiesUnknown15-Nov-2005
Luminous NetworksUnknown15-Nov-2005
Mandriva, Inc.Unknown15-Nov-2005
Microsoft CorporationNot Vulnerable15-Nov-2005
MontaVista Software, Inc.Unknown15-Nov-2005
Multinet (owned Process Software Corporation)Unknown15-Nov-2005
Multitech, Inc.Unknown15-Nov-2005
NEC CorporationVulnerable16-Dec-2005
NetBSDUnknown15-Nov-2005
Network Appliance, Inc.Unknown15-Nov-2005
NextHop Technologies, Inc.Unknown15-Nov-2005
NIST IPsec ProjectUnknown15-Nov-2005
Nortel Networks, Inc.Vulnerable30-Nov-2005
Novell, Inc.Unknown15-Nov-2005
OpenBSDUnknown15-Nov-2005
OpenBSD IPSecUnknown15-Nov-2005
Openswan Linux IPsec softwareVulnerable17-Nov-2005
Openwall GNU/*/LinuxUnknown15-Nov-2005
QNX, Software Systems, Inc.Vulnerable2-Dec-2005
Red Hat, Inc.Unknown15-Nov-2005
Redback Networks, Inc.Unknown15-Nov-2005
Riverstone Networks, Inc.Unknown15-Nov-2005
SafeNetUnknown15-Nov-2005
Secure Computing Network Security DivisionUnknown15-Nov-2005
Sequent Computer Systems, Inc.Unknown15-Nov-2005
Silicon Graphics, Inc.Unknown15-Nov-2005
Slackware Linux Inc.Unknown15-Nov-2005
Sony CorporationUnknown15-Nov-2005
SSH Communications IP SecurityUnknown15-Nov-2005
StonesoftVulnerable17-Nov-2005
Sun Microsystems, Inc.Vulnerable17-Nov-2005
SUSE LinuxUnknown15-Nov-2005
Symantec, Inc.Unknown15-Nov-2005
The SCO GroupUnknown15-Nov-2005
Trustix Secure LinuxUnknown15-Nov-2005
TurbolinuxUnknown15-Nov-2005
UbuntuUnknown15-Nov-2005
UnisysUnknown15-Nov-2005
Watchguard Technologies, Inc.Unknown15-Nov-2005
Wind River Systems, Inc.Unknown15-Nov-2005
ZyXELUnknown15-Nov-2005

References


http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp
http://www.ficora.fi/suomi/tietoturva/varoitukset/varoitus-2005-82.htm
http://www.auscert.org.au/5748
http://jvn.jp/niscc/NISCC-273756/index.html
http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=en
http://secunia.com/advisories/17608/
http://secunia.com/advisories/17621/
http://secunia.com/advisories/17553/
http://secunia.com/advisories/17684/
http://secunia.com/advisories/17668/
http://secunia.com/advisories/17663/
http://secunia.com/advisories/17838/

Credit

These vulnerabilities were reported by NISCC and CERT-FI

This document was written by Jeff Gennari.

Other Information

Date Public:2005-11-14
Date First Published:2005-11-17
Date Last Updated:2006-01-03
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:16.54
Document Revision:31

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader