PT-2016-6390 · Libreswan+2 · Libreswan+2

Published

2016-06-16

·

Updated

2017-01-18

·

CVE-2016-5361

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libreswan versions prior to 3.17
Description The issue allows remote attackers to cause a denial of service, specifically traffic amplification, via a spoofed UDP packet. This is due to the retransmission in initial-responder states. The original behavior complies with the IKEv1 protocol but has a required security update from the libreswan vendor.
Recommendations For versions prior to 3.17, update to version 3.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected ikev1.c module to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2016_2603
CVE-2016-5361
RHSA-2016:2603
RHSA-2016_2603

Affected Products

Centos
Red Hat
Libreswan