CVE-2016-3071: Input Validation
Published Apr 18, 2016
·Updated
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aesxcbc transform.
Affected Software
3 affected components
libreswan Libreswan=3.16
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Event History
Apr 18, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3071?
CVE-2016-3071 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-3071?
To resolve CVE-2016-3071, upgrade Libreswan to a version later than 3.16.
3
What systems are affected by CVE-2016-3071?
CVE-2016-3071 affects Libreswan 3.16 and specific versions of Fedora 23 and 24.
4
Can CVE-2016-3071 be exploited remotely?
Yes, CVE-2016-3071 can be exploited by remote attackers to cause a daemon restart.
5
What impact does CVE-2016-3071 have on my system?
Exploitation of CVE-2016-3071 can lead to service interruptions due to the daemon restart.