CVE-2014-9221: Medium severity strongswan vulnerability
Published Jan 7, 2015
·Updated
strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.
Affected Software
25 affected components
strongSwan Strongswan=4.5.0
strongSwan Strongswan=4.5.1
strongSwan Strongswan=4.5.2
strongSwan Strongswan=4.5.3
strongSwan Strongswan=4.6.0
strongSwan Strongswan=4.6.1
strongSwan Strongswan=4.6.2
strongSwan Strongswan=4.6.3
strongSwan Strongswan=4.6.4
strongSwan Strongswan=5.0.0
strongSwan Strongswan=5.0.1
strongSwan Strongswan=5.0.2
strongSwan Strongswan=5.0.3
strongSwan Strongswan=5.0.4
strongSwan Strongswan=5.1.0
strongSwan Strongswan=5.1.1
strongSwan Strongswan=5.1.2
strongSwan Strongswan=5.1.3
strongSwan Strongswan=5.2.0
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Fedoraproject Fedora=21
Debian Debian Linux=7.0
Event History
Jan 7, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9221?
The severity of CVE-2014-9221 is classified as a denial of service vulnerability.
2
How do I fix CVE-2014-9221?
To fix CVE-2014-9221, upgrade strongSwan to version 5.2.1 or later.
3
Which versions of strongSwan are affected by CVE-2014-9221?
Versions of strongSwan from 4.5.x through 5.2.0 are affected by CVE-2014-9221.
4
What type of attack does CVE-2014-9221 facilitate?
CVE-2014-9221 allows remote attackers to perform a denial of service via a crafted IKEv2 Key Exchange message.
5
What conditions lead to the vulnerability described in CVE-2014-9221?
The vulnerability occurs due to an invalid pointer dereference when handling a Diffie-Hellman group 1025 during the IKEv2 Key Exchange.