Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3240

Опубликовано: 25 авг. 2015
Источник: redhat
CVSS2: 5

Описание

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

A flaw was discovered in the way Libreswan's IKE daemon processed IKE KE payloads. A remote attacker could send specially crafted IKE payload with a KE payload of g^x=0 that, when processed, would lead to a denial of service (daemon crash).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openswanWill not fix
Red Hat Enterprise Linux 6openswanWill not fix
Red Hat Enterprise Linux 7libreswanFixedRHSA-2015:197904.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1232320openswan: denial of service via IKE daemon restart when receiving a bad DH gx value

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

nvd
почти 10 лет назад

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

debian
почти 10 лет назад

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6. ...

github
больше 3 лет назад

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

oracle-oval
почти 10 лет назад

ELSA-2015-1979: libreswan security and enhancement update (MODERATE)

5 Medium

CVSS2