libreswan: DoS attack via malicious IKEv1 informational exchange message
Published May 12, 2020
7.5
HIGHCVSS 3.1
EPSS 3.57%
Description
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.
Affected products
-
- Version from versions 3.27 till 3.31StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| the libreswan Project | Libreswan | n/a |
|
No data.
Red Hat Enterprise Linux 8
libreswan-0:3.29-7.el8_2
Fixed · RHSA-2020:2070
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
libreswan-0:3.27-10.el8_0
Fixed · RHSA-2020:2069
Red Hat Enterprise Linux 8.1 Extended Update Support
libreswan-0:3.29-7.el8_1
Fixed · RHSA-2020:2071
Red Hat Enterprise Linux 6
libreswan
Not affected
Red Hat Enterprise Linux 7
libreswan
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libreswan-0:3.29-7.el8_2 | Fixed | RHSA-2020:2070 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | libreswan-0:3.27-10.el8_0 | Fixed | RHSA-2020:2069 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | libreswan-0:3.29-7.el8_1 | Fixed | RHSA-2020:2071 |
| Red Hat Enterprise Linux 6 | libreswan | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libreswan | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect the version of libreswan shipped with Red Hat Enterprise Linux 6 and 7 because they did not ship the vulnerable code. (The offending commit fa004e7d4b83fbeaa8d0f6d8430a96aed97a97b9 and others was introduced in libreswan-3.27)
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
References (13)
- https://access.redhat.com/security/cve/CVE-2020-1763 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1813329 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1814541 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1763 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf x_refsource_CONFIRMThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12590 Advisory
- https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8 x_refsource_CONFIRMPatchThird Party Advisory
- https://libreswan.org/security/CVE-2020-1763/CVE-2020-1763.txt x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1763
- https://security.gentoo.org/glsa/202007-21 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04 x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2020-1763
- https://www.debian.org/security/2020/dsa-4684 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.