Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23094

Опубликовано: 11 янв. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

A vulnerability was found in libreswan. A malformed packet that is being rejected triggers a logging action that causes a NULL pointer dereference issue, leading to a crash of the pluto daemon.

Меры по смягчению последствий

If all configured connections are using IKEv2, the IKEv1 subsystem can be disabled by adding the option ikev1-policy=drop to the "config setup" section of ipsec.conf. Alternatively, libreswan can be compiled with USE_IKEv1=false. If all remote peers are on static IP addresses, a firewall rule blocking UDP port 500 and 4500 can be installed to prevent attackers from sending packets to the pluto IKE daemon. If peers appear on dynamic IP addresses and IKEv1 connections must be supported, then no workarounds are known, and libreswan must be updated or patched.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreswanNot affected
Red Hat Enterprise Linux 7libreswanNot affected
Red Hat Enterprise Linux 9libreswanNot affected
Red Hat Enterprise Linux 8libreswanFixedRHSA-2022:019919.01.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportlibreswanFixedRHSA-2022:023924.01.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2036898libreswan: Malicious IKEv1 packet can cause libreswan to restart

EPSS

Процентиль: 79%
0.01296
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

CVSS3: 7.5
nvd
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

CVSS3: 7.5
debian
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of ...

rocky
около 4 лет назад

Important: libreswan security update

github
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

EPSS

Процентиль: 79%
0.01296
Низкий

7.5 High

CVSS3