Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2016-3071
Disclosure Date: April 18, 2016 (last updated November 25, 2024)
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
0
Attacker Value
Unknown
CVE-2015-3240
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
0
Attacker Value
Unknown
CVE-2015-3204
Disclosure Date: July 01, 2015 (last updated October 05, 2023)
libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMP_NEXT_SAK.
0
Attacker Value
Unknown
CVE-2013-6467
Disclosure Date: January 26, 2014 (last updated October 05, 2023)
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
0
Attacker Value
Unknown
CVE-2013-7294
Disclosure Date: January 16, 2014 (last updated October 05, 2023)
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
0
Attacker Value
Unknown
CVE-2013-2052
Disclosure Date: July 09, 2013 (last updated October 05, 2023)
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
0