First published: Mon Nov 09 2015(Updated: )
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libreswan Libreswan | =3.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.