Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10155

Опубликовано: 12 июн. 2019
Источник: debian
EPSS Низкий

Описание

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libreswanfixed3.27-6package
strongswanfixed5.1.0-1package
openswanremovedpackage
freeswanremovedpackage

Примечания

  • https://libreswan.org/security/CVE-2019-10155/

  • Not vulnerable: libreswan 3.29 and later, strongswan 5.0 and later, freeswan

EPSS

Процентиль: 45%
0.00226
Низкий

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 6 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
redhat
больше 6 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
nvd
больше 6 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
github
больше 3 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

oracle-oval
около 6 лет назад

ELSA-2019-3391: libreswan security and bug fix update (LOW)

EPSS

Процентиль: 45%
0.00226
Низкий