{
  "schema_version": "1.6.0",
  "id": "STRONGSWAN-CVE-2008-4551",
  "aliases": [
    "CVE-2008-4551"
  ],
  "modified": "2026-09-24T16:15:49Z",
  "affected": [
    {
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "4.1.8"
            },
            {
              "fixed": "4.2.7"
            }
          ]
        },
        {
          "type": "GIT",
          "repo": "https://github.com/strongswan/strongswan.git",
          "events": [
            {
              "introduced": "b82e823141dcf0992eace4c6da6008872516ca42"
            },
            {
              "fixed": "b37cda8211ec08b5301a339cf9b01523380d9688"
            }
          ]
        }
      ]
    }
  ],
  "database_specific": {
    "package": "strongswan"
  },
  "references": [
    {
      "type": "WEB",
      "url": "https://download.strongswan.org/security/CVE-2008-4551"
    }
  ],
  "published": "2008-09-22T12:00:00Z",
  "summary": "A denial-of-service vulnerability where an IKE_SA_INIT message with a KE payload containing zeroes only can cause a crash of the IKEv2 charon daemon due to a NULL pointer returned by the mpz_export() function of the GNU Multi Precision (GMP) library."
}
