Логотип exploitDog
bind:CVE-2023-2295
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-2295

Количество 8

Количество 8

ubuntu логотип

CVE-2023-2295

больше 2 лет назад

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-2295

больше 2 лет назад

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-2295

больше 2 лет назад

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-2295

больше 2 лет назад

A vulnerability was found in the libreswan library. This security issu ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2023:3107

около 2 лет назад

Important: libreswan security update

EPSS: Низкий
github логотип

GHSA-gcrh-c42h-m2vw

около 2 лет назад

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2023-3148

больше 2 лет назад

ELSA-2023-3148: libreswan security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-3107

около 2 лет назад

ELSA-2023-3107: libreswan security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-2295

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-2295

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2295

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-2295

A vulnerability was found in the libreswan library. This security issu ...

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2023:3107

Important: libreswan security update

2%
Низкий
около 2 лет назад
github логотип
GHSA-gcrh-c42h-m2vw

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2023-3148

ELSA-2023-3148: libreswan security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-3107

ELSA-2023-3107: libreswan security update (IMPORTANT)

около 2 лет назад

Уязвимостей на страницу