PT-2016-6390 · Libreswan+2 · Libreswan+2

Publicado

2016-06-16

·

Atualizado

2017-01-18

·

CVE-2016-5361

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libreswan versions prior to 3.17
Description The issue allows remote attackers to cause a denial of service, specifically traffic amplification, via a spoofed UDP packet. This is due to the retransmission in initial-responder states. The original behavior complies with the IKEv1 protocol but has a required security update from the libreswan vendor.
Recommendations For versions prior to 3.17, update to version 3.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected ikev1.c module to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2016_2603
CVE-2016-5361
RHSA-2016:2603
RHSA-2016_2603

Produtos afetados

Centos
Red Hat
Libreswan