Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openswan | Xelerance | 2.6.29 | 2.6.29 |
Openswan | Xelerance | 2.6.30 | 2.6.30 |
Openswan | Xelerance | 2.6.31 | 2.6.31 |
Openswan | Xelerance | 2.6.32 | 2.6.32 |
Openswan | Xelerance | 2.6.33 | 2.6.33 |
Openswan | Xelerance | 2.6.34 | 2.6.34 |
Openswan | Xelerance | 2.6.35 | 2.6.35 |
Red Hat Enterprise Linux 6 | RedHat | openswan-0:2.6.32-4.el6_1.2 | * |