This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Libreswan First view 2014-01-16
Product Libreswan Last view 2020-05-12
Version 3.4 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:libreswan:libreswan

Activity : Overall

Related : CVE

  Date Alert Description
7.5 2020-05-12 CVE-2020-1763

An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.

3.1 2019-06-12 CVE-2019-10155

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

7.5 2019-05-24 CVE-2019-12312

In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IKEv2 IKE_SA_INIT exchange, followed by a bogus INFORMATIONAL exchange instead of the normallly expected IKE_AUTH exchange. This affects send_v2N_spi_response_from_state() in programs/pluto/ikev2_send.c that will then trigger a NULL pointer dereference leading to a restart of libreswan.

7.5 2017-06-13 CVE-2016-5391

libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).

7.5 2016-06-16 CVE-2016-5361

programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed UDP packet. NOTE: the original behavior complies with the IKEv1 protocol, but has a required security update from the libreswan vendor; as of 2016-06-10, it is expected that several other IKEv1 implementations will have vendor-required security updates, with separate CVE IDs assigned to each.

5 2014-01-26 CVE-2013-6467

Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.

5 2014-01-16 CVE-2013-7294

The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.

CWE : Common Weakness Enumeration

%idName
28% (2) CWE-476 NULL Pointer Dereference
28% (2) CWE-20 Improper Input Validation
14% (1) CWE-617 Reachable Assertion
14% (1) CWE-354 Improper Validation of Integrity Check Value
14% (1) CWE-125 Out-of-bounds Read

Nessus® Vulnerability Scanner

id Description
2017-05-01 Name: The remote EulerOS host is missing a security update.
File: EulerOS_SA-2016-1078.nasl - Type: ACT_GATHER_INFO
2016-12-15 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20161103_libreswan_on_SL7_x.nasl - Type: ACT_GATHER_INFO
2016-11-28 Name: The remote CentOS host is missing a security update.
File: centos_RHSA-2016-2603.nasl - Type: ACT_GATHER_INFO
2016-11-11 Name: The remote Oracle Linux host is missing a security update.
File: oraclelinux_ELSA-2016-2603.nasl - Type: ACT_GATHER_INFO
2016-11-04 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-2603.nasl - Type: ACT_GATHER_INFO
2016-08-09 Name: The remote Fedora host is missing a security update.
File: fedora_2016-d46685629d.nasl - Type: ACT_GATHER_INFO
2016-08-03 Name: The remote Fedora host is missing a security update.
File: fedora_2016-26a03340e6.nasl - Type: ACT_GATHER_INFO
2014-02-01 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_openswan-140121.nasl - Type: ACT_GATHER_INFO
2014-01-29 Name: The remote Fedora host is missing a security update.
File: fedora_2014-1092.nasl - Type: ACT_GATHER_INFO
2014-01-29 Name: The remote Fedora host is missing a security update.
File: fedora_2014-1121.nasl - Type: ACT_GATHER_INFO