First published: Mon Nov 09 2015(Updated: )
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libreswan | =3.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3240 has a medium severity rating as it allows remote attackers to induce a denial of service.
To fix CVE-2015-3240, upgrade libreswan to version 3.15 or higher, or upgrade Openswan to version 2.6.45 or higher.
CVE-2015-3240 affects libreswan versions before 3.15 and Openswan versions before 2.6.45 when built with NSS.
The impact of CVE-2015-3240 is a denial of service due to an assertion failure leading to the restart of the pluto IKE daemon.
Attackers can exploit CVE-2015-3240 by sending a zero DH g^x value in a KE payload within an IKE packet.