Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10155

Опубликовано: 10 июн. 2019
Источник: redhat
CVSS3: 3.1

Описание

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

A vulnerability was found in the Libreswan Project. It was discovered that libreswan, strongswan, and openswan did not verify the integrity check value for received IKEv1 Informational Exchange packets.

Меры по смягчению последствий

If all IKE peers support IKEv2, it is possible to reconfigure IKEv1 connections to use IKEv2 via the "ikev2=insist" keyword.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openswanOut of support scope
Red Hat Enterprise Linux 6libreswanOut of support scope
Red Hat Enterprise Linux 6openswanOut of support scope
Red Hat Enterprise Linux 7libreswanOut of support scope
Red Hat Enterprise Linux 8libreswanFixedRHSA-2019:339105.11.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-354
https://bugzilla.redhat.com/show_bug.cgi?id=1714141libreswan: vulnerability in the processing of IKEv1 informational packets due to missing integrity check

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 6 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
nvd
больше 6 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

CVSS3: 3.1
debian
больше 6 лет назад

The Libreswan Project has found a vulnerability in the processing of I ...

CVSS3: 3.1
github
больше 3 лет назад

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

oracle-oval
около 6 лет назад

ELSA-2019-3391: libreswan security and bug fix update (LOW)

3.1 Low

CVSS3