CVE-2019-10155: Low severity libreswan vulnerability
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified.
Bugzilla issue:
https://bugzilla.redhat.com/showbug.cgi?id=1713512
Other sources
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Libreswan vulnerability?
The vulnerability ID for this Libreswan vulnerability is CVE-2019-10155.
What is the severity level of CVE-2019-10155?
The severity level of CVE-2019-10155 is low with a severity value of 3.1.
How does CVE-2019-10155 affect the Libreswan software?
CVE-2019-10155 affects Libreswan versions up to 3.29 by not verifying the integrity check value of IKEv1 informational exchange packets.
What is the official reference for CVE-2019-10155?
The official references for CVE-2019-10155 are: [Red Hat Security Advisory RHSA-2019:3391](https://access.redhat.com/errata/RHSA-2019:3391), [Red Hat Bugzilla CVE-2019-10155](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10155), and [Libreswan Security Page for CVE-2019-10155](https://libreswan.org/security/CVE-2019-10155/).
How can I fix CVE-2019-10155?
To fix CVE-2019-10155, update Libreswan software to version 3.29 or above.