Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libreswan | May 4, 2022 | Jan 15, 2022 | |
| Alpine Linux | alpine-linux-upgrade-libreswan | Aug 22, 2024 | Jan 15, 2022 | |
| Centos_linux | — | centos-upgrade-libreswancentos-upgrade-libreswan-debuginfocentos-upgrade-libreswan-debugsource | Feb 17, 2022 | Jan 15, 2022 |
| Debian | debian-upgrade-libreswan | Nov 4, 2022 | Jan 15, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-libreswan | Jan 20, 2022 | Jan 11, 2022 |
| Redhat_linux | redhat-upgrade-libreswanredhat-upgrade-libreswan-debuginforedhat-upgrade-libreswan-debugsource | Jan 21, 2022 | Jan 15, 2022 | |
| Rocky_linux | rocky-upgrade-libreswanrocky-upgrade-libreswan-debuginforocky-upgrade-libreswan-debugsource | Mar 12, 2024 | Jan 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub