Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-38712

Опубликовано: 25 авг. 2023
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libreswanfixed4.12-1package
libreswanend-of-lifebullseyepackage

Примечания

  • https://libreswan.org/security/CVE-2023-38712/CVE-2023-38712.txt

  • https://libreswan.org/security/CVE-2023-38712/CVE-2023-38712.patch

EPSS

Процентиль: 13%
0.00045
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

CVSS3: 6.5
redhat
около 2 лет назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

CVSS3: 6.5
nvd
около 2 лет назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

CVSS3: 6.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.5
github
около 2 лет назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

EPSS

Процентиль: 13%
0.00045
Низкий