Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
References
Configurations
History
No history.
Information
Published : 2022-01-15 02:15
Updated : 2024-11-21 06:47
NVD link : CVE-2022-23094
Mitre link : CVE-2022-23094
CVE.ORG link : CVE-2022-23094
JSON object : View
Products Affected
fedoraproject
- fedora
debian
- debian_linux
libreswan
- libreswan
CWE
CWE-476
NULL Pointer Dereference