CVE-2020-1763
Published on: 05/12/2020 12:00:00 AM UTC
Last Modified on: 05/05/2021 01:41:00 PM UTC
Certain versions of Libreswan from Libreswan contain the following vulnerability:
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.
- CVE-2020-1763 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
the libreswan Project - libreswan version from versions 3.27 till 3.31
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Siemens RUGGEDCOM ROX II | CISA | us-cert.cisa.gov text/html |
![]() |
1814541 – (CVE-2020-1763) CVE-2020-1763 libreswan: DoS attack via malicious IKEv1 informational exchange message | Issue Tracking Third Party Advisory bugzilla.redhat.com text/html |
![]() |
Debian -- Security Information -- DSA-4684-1 libreswan | Third Party Advisory www.debian.org Depreciated Link text/html |
![]() |
Patch Vendor Advisory libreswan.org text/x-diff |
![]() | |
security: Fix for CVE-2020-1763 · libreswan/[email protected] · GitHub | Patch Third Party Advisory github.com text/html |
![]() |
cert-portal.siemens.com application/pdf |
![]() | |
Libreswan: Denial of service (GLSA 202007-21) — Gentoo security | security.gentoo.org text/html |
![]() |
Bug Access Denied | Issue Tracking Third Party Advisory bugzilla.redhat.com text/html |
![]() |
Related QID Numbers
- 501057 Alpine Linux Security Update for libreswan
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Libreswan | Libreswan | 3.5 | All | All | All |
Application | Libreswan | Libreswan | 3.5 | All | All | All |
Application | Libreswan | Libreswan | All | All | All | All |
- cpe:2.3:a:libreswan:libreswan:3.5:*:*:*:*:*:*:*:
- cpe:2.3:a:libreswan:libreswan:3.5:*:*:*:*:*:*:*:
- cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|