PT-2014-1910 · Openswan+2 · Openswan+2

Iustina Melinte

·

Published

2014-01-26

·

Updated

2019-07-29

·

CVE-2013-6466

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Openswan versions prior to 2.6.39
Description The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and IKE daemon restart, via IKEv2 packets that lack expected payloads. This can lead to disruption of protected information availability. The exploitation of this issue can be performed remotely.
Recommendations For versions prior to 2.6.39, update to a version later than 2.6.39 to resolve the issue. As a temporary workaround, consider restricting access to IKEv2 packets to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09776
CESA-2014_0185
CVE-2013-6466
DSA-2893-1
MGASA-2014-0097
RHSA-2014:0185
RHSA-2014_0185

Affected Products

Centos
Openswan
Red Hat