Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libreswan | May 4, 2022 | Jan 15, 2022 |
| Alpine Linux | — | Upgrade libreswan | Aug 22, 2024 | Jan 15, 2022 |
| Centos_linux | — | Upgrade libreswan-debuginfoUpgrade libreswanUpgrade libreswan-debugsource | Feb 17, 2022 | Jan 15, 2022 |
| Debian | — | Upgrade libreswan | Nov 4, 2022 | Jan 15, 2022 |
| Oracle_linux | — | Upgrade libreswan | Jan 20, 2022 | Jan 11, 2022 |
| Redhat_linux | — | Upgrade libreswan-debuginfoUpgrade libreswanUpgrade libreswan-debugsource | Jan 21, 2022 | Jan 15, 2022 |
| Rocky_linux | — | Upgrade libreswanUpgrade libreswan-debuginfoUpgrade libreswan-debugsource | Mar 12, 2024 | Jan 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub