REDHAT-BUG-1356183: Medium severity libreswan vulnerability
Published Jul 13, 2016
·Updated
A vulnerability was found in libreswan 3.17. IKEv2 bogus proposal lacking DH transform causes pluto daemon to restart.
Affected Software
1 affected component
libreswan Libreswan
Event History
Jul 13, 2016
Data Sourced
via Red Hat·03:12 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1356183?
The severity of REDHAT-BUG-1356183 is considered to be high due to the potential for service disruption.
2
How do I fix REDHAT-BUG-1356183?
To fix REDHAT-BUG-1356183, update libreswan to a patched version that resolves the vulnerability.
3
What impact does REDHAT-BUG-1356183 have on system security?
REDHAT-BUG-1356183 can lead to the pluto daemon restarting, which may disrupt connectivity and expose the system to further risks.
4
Is my system affected by REDHAT-BUG-1356183?
If you are using libreswan version 3.17, your system is affected by REDHAT-BUG-1356183.
5
What should I do if I cannot update due to REDHAT-BUG-1356183?
If you cannot update, consider implementing network controls to limit exposure until you can apply the necessary patches for REDHAT-BUG-1356183.