First published: Wed Jul 13 2016(Updated: )
A vulnerability was found in libreswan 3.17. IKEv2 bogus proposal lacking DH transform causes pluto daemon to restart.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libreswan | <=3.17 | |
Red Hat Fedora | =23 | |
Red Hat Fedora | =24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5391 has a severity rating that indicates it allows remote attackers to cause a denial of service.
The vulnerability CVE-2016-5391 is caused by a bogus IKEv2 proposal lacking a DH transform, leading to a NULL pointer dereference.
To fix CVE-2016-5391, upgrade Libreswan to version 3.18 or later.
CVE-2016-5391 affects Libreswan versions prior to 3.18, including 3.17.
Yes, CVE-2016-5391 affects certain Fedora versions, including Fedora 23 and Fedora 24.