The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
References
Link | Resource |
---|---|
http://secunia.com/advisories/56276 | Vendor Advisory |
http://secunia.com/advisories/56915 | |
http://www.osvdb.org/101573 | |
https://github.com/libreswan/libreswan/commit/2899351224fe2940aec37d7656e1e392c0fe07f0 | Exploit Patch |
https://lists.libreswan.org/pipermail/swan-announce/2013/000007.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2014-01-16T02:00:00
Updated: 2018-01-02T19:57:01
Reserved: 2014-01-15T00:00:00
Link: CVE-2013-7294
JSON object: View
NVD Information
Status : Modified
Published: 2014-01-16T05:05:26.523
Modified: 2018-01-03T02:29:00.240
Link: CVE-2013-7294
JSON object: View
Redhat Information
No data.
CWE