Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3204

Опубликовано: 01 июн. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMP_NEXT_SAK.

A flaw was discovered in the way Libreswan's IKE daemon processed certain IKEv1 payloads. A remote attacker could send specially crafted IKEv1 payloads that, when processed, would lead to a denial of service (daemon crash).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openswanNot affected
Red Hat Enterprise Linux 6openswanNot affected
Red Hat Enterprise Linux 7libreswanFixedRHSA-2015:115423.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1223361libreswan: crafted IKE packet causes daemon restart

EPSS

Процентиль: 68%
0.00588
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
около 10 лет назад

libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMP_NEXT_SAK.

debian
около 10 лет назад

libreswan 3.9 through 3.12 allows remote attackers to cause a denial o ...

github
больше 3 лет назад

libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMP_NEXT_SAK.

oracle-oval
около 10 лет назад

ELSA-2015-1154: libreswan security, bug fix and enhancement update (MODERATE)

EPSS

Процентиль: 68%
0.00588
Низкий

4.3 Medium

CVSS2