CVE-2013-6076: Null Pointer Dereference
Published Nov 2, 2013
·Updated
strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted IKEv1 fragmentation packet.
Affected Software
4 affected components
strongSwan Strongswan=5.0.2
strongSwan Strongswan=5.0.3
strongSwan Strongswan=5.0.4
strongSwan Strongswan=5.1.0
Remediation
Event History
Nov 2, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-6076?
CVE-2013-6076 has a medium severity rating as it allows remote attackers to cause a denial of service.
2
How do I fix CVE-2013-6076?
To fix CVE-2013-6076, update strongSwan to version 5.1.1 or later, which contains a patch for this vulnerability.
3
Which versions of strongSwan are affected by CVE-2013-6076?
The affected versions of strongSwan include 5.0.2 to 5.1.0.
4
What are the potential impacts of CVE-2013-6076?
The potential impact of CVE-2013-6076 includes a crash of the charon daemon, leading to service disruption.
5
Can I mitigate CVE-2013-6076 without updating?
No effective mitigation is available without updating to a patched version for CVE-2013-6076.