Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-38712

Опубликовано: 25 авг. 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 4.0 (исключая)
cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.12 (исключая)

EPSS

Процентиль: 14%
0.00045
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

CVSS3: 6.5
redhat
почти 2 года назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

CVSS3: 6.5
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 2 года назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an ...

CVSS3: 7.5
github
почти 2 года назад

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

EPSS

Процентиль: 14%
0.00045
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476