CVE Vulnerabilities

CVE-2014-9221

Published: Jan 07, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.

Affected Software

NameVendorStart VersionEnd Version
StrongswanStrongswan4.5.0 (including)4.5.0 (including)
StrongswanStrongswan4.5.1 (including)4.5.1 (including)
StrongswanStrongswan4.5.2 (including)4.5.2 (including)
StrongswanStrongswan4.5.3 (including)4.5.3 (including)
StrongswanStrongswan4.6.0 (including)4.6.0 (including)
StrongswanStrongswan4.6.1 (including)4.6.1 (including)
StrongswanStrongswan4.6.2 (including)4.6.2 (including)
StrongswanStrongswan4.6.3 (including)4.6.3 (including)
StrongswanStrongswan4.6.4 (including)4.6.4 (including)
StrongswanStrongswan5.0.0 (including)5.0.0 (including)
StrongswanStrongswan5.0.1 (including)5.0.1 (including)
StrongswanStrongswan5.0.2 (including)5.0.2 (including)
StrongswanStrongswan5.0.3 (including)5.0.3 (including)
StrongswanStrongswan5.0.4 (including)5.0.4 (including)
StrongswanStrongswan5.1.0 (including)5.1.0 (including)
StrongswanStrongswan5.1.1 (including)5.1.1 (including)
StrongswanStrongswan5.1.2 (including)5.1.2 (including)
StrongswanStrongswan5.1.3 (including)5.1.3 (including)
StrongswanStrongswan5.2.0 (including)5.2.0 (including)
StrongswanUbuntudevel*
StrongswanUbuntuesm-infra-legacy/trusty*
StrongswanUbuntuesm-infra/xenial*
StrongswanUbuntulucid*
StrongswanUbuntuprecise*
StrongswanUbuntutrusty*
StrongswanUbuntutrusty/esm*
StrongswanUbuntuupstream*
StrongswanUbuntuutopic*
StrongswanUbuntuvivid*
StrongswanUbuntuwily*
StrongswanUbuntuxenial*
StrongswanUbuntuyakkety*
StrongswanUbuntuzesty*

References