CVE-2014-2891: Null Pointer Dereference
Published May 7, 2014
·Updated
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted IDDERASN1DN ID payload.
Affected Software
8 affected components
Debian Strongswan<=5.1.2
strongSwan Strongswan<=5.1.1
strongSwan Strongswan=5.0.0
strongSwan Strongswan=5.0.1
strongSwan Strongswan=5.0.2
strongSwan Strongswan=5.0.3
strongSwan Strongswan=5.0.4
strongSwan Strongswan=5.1.0
Event History
May 7, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2891?
CVE-2014-2891 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2014-2891?
To fix CVE-2014-2891, upgrade strongSwan to version 5.1.2 or later.
3
What type of attack does CVE-2014-2891 allow?
CVE-2014-2891 allows remote attackers to trigger a denial of service by causing a NULL pointer dereference.
4
Which versions of strongSwan are affected by CVE-2014-2891?
strongSwan versions prior to 5.1.2, including 5.1.1 and earlier, are affected by CVE-2014-2891.
5
What components are impacted by CVE-2014-2891?
CVE-2014-2891 primarily impacts the IKE daemon of the strongSwan VPN solution.