Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-2357

Опубликовано: 11 мар. 2024
Источник: debian
EPSS Низкий

Описание

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libreswanfixed4.14-1package
libreswanno-dsabookwormpackage
libreswanend-of-lifebullseyepackage

Примечания

  • https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.patch

  • https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.txt

  • https://github.com/libreswan/libreswan/issues/1609

  • Fixed by: https://github.com/libreswan/libreswan/commit/cb9e1047d33fde695d63a95854c2bc2470a476c8

EPSS

Процентиль: 60%
0.00396
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.

CVSS3: 5
redhat
больше 1 года назад

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.

CVSS3: 6.5
nvd
больше 1 года назад

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.

CVSS3: 7.5
redos
около 1 года назад

Уязвимость xl2tpd

CVSS3: 7.5
redos
около 1 года назад

Уязвимость libreswan

EPSS

Процентиль: 60%
0.00396
Низкий