Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-395v-96gv-76w3

Опубликовано: 11 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

CVSS3: 6.5
redhat
почти 2 года назад

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

CVSS3: 6.5
nvd
почти 2 года назад

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

CVSS3: 6.5
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 2 года назад

The Libreswan Project was notified of an issue causing libreswan to re ...

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-404