CVE-2009-1574

ipsec-tools < 0.7.2 - Denial of Service via Crafted Fragmented Packets

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1574. PoCs published by mu-b.

AI-analyzed exploit summary This exploit sends a malformed ISAKMP fragmentation payload to trigger a denial-of-service (DoS) in ipsec-tools racoon. It constructs a UDP packet with a crafted ISAKMP header and fragmentation payload, causing the target service to crash.

Description

racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.

Exploits (1)

exploitdb WORKING POC VERIFIED
by mu-b · cdosmultiple
https://www.exploit-db.com/exploits/8669

This exploit sends a malformed ISAKMP fragmentation payload to trigger a denial-of-service (DoS) in ipsec-tools racoon. It constructs a UDP packet with a crafted ISAKMP header and fragmentation payload, causing the target service to crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: ipsec-tools racoon 0.7.1
No auth needed
Prerequisites: Network access to the target's ISAKMP port (UDP 500)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (28)

Core 28
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:112
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50412
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-785-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35159
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00789.html
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/04/29/6
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34765
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1036.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35113
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9624
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35404
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/05/04/3
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35212
Exploit, Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=497990
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200905-03.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35685
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00746.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4298
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3184
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35153
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00725.html
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1804
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3937

Scores

EPSS 0.1163
EPSS Percentile 95.5%

Details

Status published
Products (20)
ipsec-tools/ipsec-tools 0.1
ipsec-tools/ipsec-tools 0.2
ipsec-tools/ipsec-tools 0.2.1
ipsec-tools/ipsec-tools 0.2.2
ipsec-tools/ipsec-tools 0.2.3
ipsec-tools/ipsec-tools 0.2.4
ipsec-tools/ipsec-tools 0.3 (6 CPE variants)
ipsec-tools/ipsec-tools 0.3.1
ipsec-tools/ipsec-tools 0.3.2
ipsec-tools/ipsec-tools 0.3.3
... and 10 more
Published May 06, 2009
Tracked Since Feb 18, 2026