CVE-2014-2037: Input Validation
Published Nov 26, 2014
·Updated
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vulnerability exists because of an incomplete fix for CVE 2013-6466.
Affected Software
1 affected component
Xelerance Openswan=2.6.40
Event History
Nov 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2037?
CVE-2014-2037 is considered a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2014-2037?
To mitigate CVE-2014-2037, upgrade Openswan to a version that addresses this vulnerability.
3
What version of Openswan is affected by CVE-2014-2037?
Openswan version 2.6.40 is affected by CVE-2014-2037.
4
Can CVE-2014-2037 be exploited remotely?
Yes, CVE-2014-2037 can be exploited remotely by sending specific IKEv2 packets.
5
What is the impact of CVE-2014-2037 on system operations?
CVE-2014-2037 can result in a denial of service, causing the IKE daemon to restart unexpectedly.