CVE-2016-5391: Null Pointer Dereference
Published Jul 13, 2016
·Updated
A vulnerability was found in libreswan 3.17. IKEv2 bogus proposal lacking DH transform causes pluto daemon to restart.
Other sources
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
— MITRE
Affected Software
3 affected components
libreswan Libreswan<=3.17
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Remediation
Event History
Jul 13, 2016
Data Sourced
03:12 PM
DescriptionSeverityAffected Software
Jun 13, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5391?
CVE-2016-5391 has a severity rating that indicates it allows remote attackers to cause a denial of service.
2
What causes the vulnerability CVE-2016-5391?
The vulnerability CVE-2016-5391 is caused by a bogus IKEv2 proposal lacking a DH transform, leading to a NULL pointer dereference.
3
How do I fix CVE-2016-5391?
To fix CVE-2016-5391, upgrade Libreswan to version 3.18 or later.
4
Which software versions are affected by CVE-2016-5391?
CVE-2016-5391 affects Libreswan versions prior to 3.18, including 3.17.
5
Is CVE-2016-5391 specific to any operating systems?
Yes, CVE-2016-5391 affects certain Fedora versions, including Fedora 23 and Fedora 24.