Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-23009

Опубликовано: 21 фев. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.

A flaw was found in the Libreswan package. A crafted TS payload with an incorrect selector length may allow a remote attacker to cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libreswanNot affected
Red Hat Enterprise Linux 8libreswanFixedRHSA-2023:309516.05.2023
Red Hat Enterprise Linux 9libreswanFixedRHSA-2023:263309.05.2023
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionslibreswanFixedRHSA-2024:1059402.12.2024
Red Hat OpenShift Container Platform 4.15libreswanFixedRHBA-2024:1156502.01.2025
Red Hat OpenShift Container Platform 4.16libreswanFixedRHBA-2024:1150502.01.2025
Red Hat OpenShift Container Platform 4.17libreswanFixedRHBA-2024:1152502.01.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2173610libreswan: remote DoS via crafted TS payload with an incorrect selector length

EPSS

Процентиль: 53%
0.00302
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.

CVSS3: 6.5
nvd
больше 2 лет назад

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.

CVSS3: 6.5
debian
больше 2 лет назад

Libreswan 4.9 allows remote attackers to cause a denial of service (as ...

CVSS3: 7.5
github
больше 2 лет назад

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.

oracle-oval
больше 2 лет назад

ELSA-2023-3095: libreswan security and bug fix update (MODERATE)

EPSS

Процентиль: 53%
0.00302
Низкий

6.5 Medium

CVSS3