PT-2011-1145 · Openswan+1 · Openswan+1

Publicado

2011-10-05

·

Atualizado

2019-07-29

·

CVE-2011-3380

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Openswan versions 2.6.29 through 2.6.35
Description The issue allows remote attackers to cause a denial of service, leading to a disruption in the confidentiality, integrity, and availability of protected information. This can be achieved through an ISAKMP message with an invalid KEY LENGTH attribute, which is not properly handled by the error handling function.
Recommendations For Openswan versions 2.6.29 through 2.6.35, consider applying a patch or update that properly handles the KEY LENGTH attribute in ISAKMP messages to prevent the denial of service. As a temporary workaround, restrict access to the pluto IKE daemon to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07486
BDU:2015-07487
BDU:2015-07488
CVE-2011-3380
RHSA-2011:1356
RHSA-2011_1356

Produtos afetados

Openswan
Red Hat