CVE-2013-4564: Medium severity libreswan vulnerability
Published Jan 7, 2014
·Updated
Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet.
Affected Software
1 affected component
libreswan Libreswan=3.6
Remediation
Event History
Jan 7, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4564?
CVE-2013-4564 has a critical severity as it allows remote attackers to cause a denial of service.
2
How do I fix CVE-2013-4564?
To fix CVE-2013-4564, upgrade to a patched version of Libreswan after 3.6.
3
What are the consequences of CVE-2013-4564?
The consequence of CVE-2013-4564 is that it may lead to a crash of the Libreswan service.
4
Which versions of Libreswan are affected by CVE-2013-4564?
Only Libreswan version 3.6 is affected by CVE-2013-4564.
5
Is CVE-2013-4564 exploitable over the network?
Yes, CVE-2013-4564 is exploitable over the network since it involves processing IKE packets.