An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libreswan | Aug 22, 2024 | May 12, 2020 |
| Centos_linux | — | Upgrade libreswanUpgrade libreswan-debugsourceUpgrade libreswan-debuginfo | May 13, 2020 | May 12, 2020 |
| Debian | — | Upgrade libreswan | May 15, 2020 | May 12, 2020 |
| Gentoo Linux | — | Upgrade net-vpn/libreswan. | Jul 28, 2020 | May 12, 2020 |
| Oracle_linux | — | Upgrade libreswan | Oct 5, 2022 | May 11, 2020 |
| Redhat_linux | — | Upgrade libreswanUpgrade libreswan-debuginfoUpgrade libreswan-debugsource | May 13, 2020 | May 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub