CVE Vulnerabilities

CVE-2015-3240

Published: Nov 09, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

Affected Software

Name Vendor Start Version End Version
Libreswan Libreswan 3.14 (including) 3.14 (including)
Libreswan Ubuntu upstream *
Openswan Ubuntu precise *
Openswan Ubuntu trusty *
Openswan Ubuntu upstream *
Red Hat Enterprise Linux 7 RedHat libreswan-0:3.15-5.el7_1 *

References