CVE-2015-3204: Input Validation
Published Jul 1, 2015
·Updated
libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMPNEXTSAK.
Affected Software
4 affected components
libreswan Libreswan=3.9
libreswan Libreswan=3.10
libreswan Libreswan=3.11
libreswan Libreswan=3.12
Event History
Jul 1, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3204?
CVE-2015-3204 has a high severity rating due to its potential to cause a denial of service by restarting the daemon.
2
How do I fix CVE-2015-3204?
To fix CVE-2015-3204, update Libreswan to a version later than 3.12.
3
Which versions of Libreswan are affected by CVE-2015-3204?
Versions 3.9 to 3.12 of Libreswan are affected by CVE-2015-3204.
4
What type of attack is related to CVE-2015-3204?
CVE-2015-3204 is associated with a denial of service attack that can be triggered by malformed IKEv1 packets.
5
Is there a workaround for CVE-2015-3204 if I cannot update?
There are no documented workarounds for CVE-2015-3204, so the best option is to upgrade to a secure version.