Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10155

Опубликовано: 12 июн. 2019
Источник: debian

Описание

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libreswanfixed3.27-6package
strongswanfixed5.1.0-1package
openswanremovedpackage
freeswanremovedpackage

Примечания

  • https://libreswan.org/security/CVE-2019-10155/

  • Not vulnerable: libreswan 3.29 and later, strongswan 5.0 and later, freeswan

Связанные уязвимости

CVSS3: 3.1
ubuntu
около 7 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
redhat
около 7 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
nvd
около 7 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
github
около 4 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

oracle-oval
больше 6 лет назад

ELSA-2019-3391: libreswan security and bug fix update (LOW)