PT-2023-5263 · Libreswan+5 · Libreswan+5
Publicado
2023-08-08
·
Atualizado
2024-03-24
·
CVE-2023-38712
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Libreswan versions 3.x and 4.x before 4.12
Description
An issue was discovered in Libreswan when an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart. This issue is related to insufficient input validation in the handling of IKEv1 ISAKMP SA packets, which can allow a remote attacker to perform a denial-of-service attack.
Recommendations
For Libreswan versions 3.x and 4.x before 4.12, update to version 4.12 or later to resolve the issue.
As a temporary workaround, consider restricting the handling of IKEv1 ISAKMP SA Informational Exchange packets to minimize the risk of exploitation.
Correção
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Almalinux
Centos
Debian
Libreswan
Red Hat
Red Os