CVE-2013-7294: Input Validation
Published Jan 16, 2014
·Updated
The ikev2parentinI1outR1 function in pluto/ikev2parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
Affected Software
7 affected components
libreswan Libreswan<=3.6
libreswan Libreswan=3.0
libreswan Libreswan=3.1
libreswan Libreswan=3.2
libreswan Libreswan=3.3
libreswan Libreswan=3.4
libreswan Libreswan=3.5
Remediation
Event History
Jan 16, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·05:05 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7294?
CVE-2013-7294 has a severity classified as a denial of service vulnerability that may lead to system restarts.
2
How do I fix CVE-2013-7294?
To fix CVE-2013-7294, you should upgrade Libreswan to version 3.7 or later.
3
What versions of Libreswan are affected by CVE-2013-7294?
CVE-2013-7294 affects Libreswan versions 3.0 to 3.6 inclusive.
4
Can CVE-2013-7294 be exploited remotely?
Yes, CVE-2013-7294 can be exploited by remote attackers through specific IKEv2 notifications.
5
What impact does CVE-2013-7294 have on system availability?
CVE-2013-7294 can cause unintended system restarts, impacting the availability of services.