Back

LOW

libreswan: vulnerability in the processing of IKEv1 informational packets due to missing integrity check

Published Jun 12, 2019

Description

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

Affected products

Remediation

Red Hat mitigation

If all IKE peers support IKEv2, it is possible to reconfigure IKEv1 connections to use IKEv2 via the "ikev2=insist" keyword.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 12, 2019
Updated Aug 4, 2024
Reserved Mar 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 10, 2019