PT-2011-1145 · Openswan+1 · Openswan+1

Published

2011-10-05

·

Updated

2019-07-29

·

CVE-2011-3380

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Openswan versions 2.6.29 through 2.6.35
Description The issue allows remote attackers to cause a denial of service, leading to a disruption in the confidentiality, integrity, and availability of protected information. This can be achieved through an ISAKMP message with an invalid KEY LENGTH attribute, which is not properly handled by the error handling function.
Recommendations For Openswan versions 2.6.29 through 2.6.35, consider applying a patch or update that properly handles the KEY LENGTH attribute in ISAKMP messages to prevent the denial of service. As a temporary workaround, restrict access to the pluto IKE daemon to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07486
BDU:2015-07487
BDU:2015-07488
CVE-2011-3380
RHSA-2011:1356
RHSA-2011_1356

Affected Products

Openswan
Red Hat