A Security Vulnerability in the "libike" Library May Affect the in.iked(1M) Daemon



Category :Security
Release Phase :Resolved
Product :Solaris 9 Operating System
Solaris 10 Operating System  
Bug Id :6317027  
Date of Workaround Release :14-NOV-2005 
Date of Resolved Release :15-DEC-2005 


Impact

A remote privileged user may be able to attempt an IKE exchange using a malformed payload, which could cause the in.iked(1M) process to crash, causing a Denial of Service (DoS) of IPSec key management services.

This issue is revealed by the test suite which is described in NISCC vulnerability #273756, which is available at http://www.uniras.gov.uk/niscc/docs/br-20051114-01013.html?lang=en


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

x86 Platform

Notes:

  1. Solaris 8 is not affected by this issue.
  2. The described issue only affects systems running the IKE (Internet Key Exchange) daemon in.iked(1M).

To determine if the in.iked(1M) is running on a system, the following command can be run:

    # pgrep -l in.iked
    368 in.iked

Symptoms

If this issue has been exploited, the IKE daemon would no longer be running. To determine that the IKE (in.iked(1M)) daemon is NOT running on a system, the following command can be run:

    $ pgrep in.iked || echo "in.iked not running"

Workaround

There is no workaround. Please see the "Resolution" section below.


Resolution

This issue is addressed in the following releases:

SPARC Platform

x86 Platform




Modification History


Date: 15-DEC-2005
  • State: Resolved
  • Updated Contributing Factors, Relief/Workaround, and Resolution sections



Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 201142
Article Type : Sun Alert
Last reviewed : 2006-04-25
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article