MEDIUM
libreswan: dereferencing missing IKEv2 payloads causes pluto daemon to restart
Published Jan 26, 2014
5.0
MEDIUMCVSS 2.0
EPSS 2.47%
Description
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
Affected products
No data.
OR
- ≤ 3.7
- 3.0
- 3.1
- 3.2
- 3.3
- 3.4
- 3.5
- 3.6
No data.
Red Hat Enterprise Linux 7
libreswan
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libreswan | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://osvdb.org/102172 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/56420 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/64987 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-6467 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1050245 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90522 vdb-entryx_refsource_XF
- https://libreswan.org/security/CVE-2013-6467/CVE-2013-6467.txt x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-6467
- https://www.cve.org/CVERecord?id=CVE-2013-6467
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/102172 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/56420 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/64987 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2013-6467 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1050245 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/90522 | vdb-entryx_refsource_XF | |
| https://libreswan.org/security/CVE-2013-6467/CVE-2013-6467.txt | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-6467 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-6467 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 26, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
Link CVE-2013-6467
CISA Vulnrichment
Updated n/a