The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-01-16 05:05
Updated : 2025-04-11 00:51
NVD link : CVE-2013-7294
Mitre link : CVE-2013-7294
CVE.ORG link : CVE-2013-7294
JSON object : View
Products Affected
libreswan
- libreswan
CWE
CWE-20
Improper Input Validation