Vulnerabilities
Vulnerable Software
Libreswan:  >> Libreswan  Security Vulnerabilities
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
CVSS Score
5.0
EPSS Score
0.025
Published
2014-01-16
Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack vectors, involving the /var/tmp/libreswan-nss-pwd temporary file.
CVSS Score
9.3
EPSS Score
0.016
Published
2014-01-09
Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet.
CVSS Score
5.0
EPSS Score
0.026
Published
2014-01-07
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
CVSS Score
5.1
EPSS Score
0.018
Published
2013-07-09


Contact Us

Shodan ® - All rights reserved