PT-2023-5265 · Libreswan+5 · Libreswan+5

Published

2023-08-08

·

Updated

2024-03-24

·

CVE-2023-38711

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Libreswan versions prior to 4.12
Description An issue was discovered in Libreswan when an IKEv1 Quick Mode connection configured with ID IPV4 ADDR or ID IPV6 ADDR receives an IDcr payload with ID FQDN, causing a NULL pointer dereference. This results in a crash and restart of the pluto daemon, potentially allowing a remote attacker to perform a denial-of-service attack.
Recommendations For versions prior to 4.12, update to version 4.12 or later to resolve the issue. As a temporary workaround, consider restricting the use of IKEv1 Quick Mode connections with ID IPV4 ADDR or ID IPV6 ADDR to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2023:6549
ALSA-2023:7052
AZL-28065
AZL-34936
BDU:2023-05882
CESA-2023_7052
CVE-2023-38711
MGASA-2024-0085
OESA-2023-1581
RHSA-2023:6549
RHSA-2023:7052
RHSA-2023_6549
RHSA-2023_7052
RHSA-2024:10594
RHSA-2025:0309

Affected Products

Almalinux
Centos
Debian
Libreswan
Red Hat
Red Os