CVE-2023-23009: Medium severity libreswan vulnerability
A crafted TS payload with an incorrect selector length may allow a remote attacker to cause a denial of service.
Other sources
Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-23009?
CVE-2023-23009 is a vulnerability in Libreswan 4.9 that allows remote attackers to cause a denial of service by triggering an assert failure and daemon restart with a crafted TS payload.
How does CVE-2023-23009 affect Libreswan?
CVE-2023-23009 affects Libreswan 4.9, leading to a denial of service issue.
What is the severity of CVE-2023-23009?
CVE-2023-23009 has a severity rating of 6.5 (medium).
How can I fix CVE-2023-23009 on Debian Linux?
To fix CVE-2023-23009 on Debian Linux, update the libreswan package to version 4.3-1+deb11u3 or later.
Where can I find more information about CVE-2023-23009?
You can find more information about CVE-2023-23009 at the following references: [link1], [link2], [link3].