The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libreswan | Libreswan | 3.14 (including) | 3.14 (including) |
Libreswan | Ubuntu | upstream | * |
Openswan | Ubuntu | precise | * |
Openswan | Ubuntu | trusty | * |
Openswan | Ubuntu | upstream | * |
Red Hat Enterprise Linux 7 | RedHat | libreswan-0:3.15-5.el7_1 | * |