PT-2019-11601 · Libreswan+2 · Libreswan+2

Published

2019-06-12

·

Updated

2020-09-30

·

CVE-2019-10155

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Libreswan versions prior to 3.29
Description: A vulnerability was found in the processing of IKEv1 informational exchange packets. These packets are encrypted and integrity protected using the established IKE SA encryption and integrity keys. However, as a receiver, the integrity check value was not verified.
Recommendations: For versions prior to 3.29, update to version 3.29 or later to resolve the issue. As a temporary workaround, consider restricting the use of IKEv1 informational exchange packets until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2019_3391
CVE-2019-10155
MGASA-2019-0210
RHSA-2019:3391
RHSA-2019_3391

Affected Products

Centos
Libreswan
Red Hat