CVE Vulnerabilities

CVE-2011-3380

Published: Nov 17, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.

Affected Software

NameVendorStart VersionEnd Version
OpenswanXelerance2.6.29 (including)2.6.29 (including)
OpenswanXelerance2.6.30 (including)2.6.30 (including)
OpenswanXelerance2.6.31 (including)2.6.31 (including)
OpenswanXelerance2.6.32 (including)2.6.32 (including)
OpenswanXelerance2.6.33 (including)2.6.33 (including)
OpenswanXelerance2.6.34 (including)2.6.34 (including)
OpenswanXelerance2.6.35 (including)2.6.35 (including)
Red Hat Enterprise Linux 6RedHatopenswan-0:2.6.32-4.el6_1.2*

References