CVE-2015-3240: Medium severity libreswan vulnerability
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3240?
CVE-2015-3240 has a medium severity rating as it allows remote attackers to induce a denial of service.
How do I fix CVE-2015-3240?
To fix CVE-2015-3240, upgrade libreswan to version 3.15 or higher, or upgrade Openswan to version 2.6.45 or higher.
What does CVE-2015-3240 affect?
CVE-2015-3240 affects libreswan versions before 3.15 and Openswan versions before 2.6.45 when built with NSS.
What is the impact of CVE-2015-3240?
The impact of CVE-2015-3240 is a denial of service due to an assertion failure leading to the restart of the pluto IKE daemon.
How can attackers exploit CVE-2015-3240?
Attackers can exploit CVE-2015-3240 by sending a zero DH g^x value in a KE payload within an IKE packet.