Unrated severityNVD Advisory· Published Apr 1, 2009· Updated Jun 16, 2026
CVE-2009-0790
CVE-2009-0790
Description
The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
64cpe:2.3:a:strongswan:strongswan:2.4.0:*:*:*:*:*:*:*+ 34 more
- cpe:2.3:a:strongswan:strongswan:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.4.0a:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.5:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.7:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:2.8.8:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.13:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:strongswan:strongswan:4.2.9:*:*:*:*:*:*:*
- (no CPE)range: <4.2.14
cpe:2.3:a:xelerance:openswan:2.4.0:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:xelerance:openswan:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.4.9:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.03:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.04:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.05:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.06:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.07:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.08:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.09:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.10:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.11:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.12:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.13:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.14:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.15:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.16:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.17:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.18:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.19:*:*:*:*:*:*:*
- cpe:2.3:a:xelerance:openswan:2.6.20:*:*:*:*:*:*:*
- Range: <2.4.14
Patches
Vulnerability mechanics
References
17- www.debian.org/security/2009/dsa-1759nvdPatch
- www.debian.org/security/2009/dsa-1760nvdPatch
- www.securityfocus.com/bid/34296nvdPatch
- download.strongswan.org/CHANGES4.txtnvdVendor Advisory
- secunia.com/advisories/34472nvdVendor Advisory
- secunia.com/advisories/34483nvdVendor Advisory
- secunia.com/advisories/34494nvdVendor Advisory
- secunia.com/advisories/34546nvdVendor Advisory
- www.openswan.org/CVE-2009-0790/CVE-2009-0790.txtnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlnvd
- www.redhat.com/support/errata/RHSA-2009-0402.htmlnvd
- www.securityfocus.com/archive/1/502270/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2009/0886nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/49523nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11171nvd
News mentions
0No linked articles in our index yet.