CVE-2023-23009
Summary
| CVE | CVE-2023-23009 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-21 16:15:00 UTC |
| Updated | 2023-11-07 04:07:00 UTC |
| Description | Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5368-1 libreswan |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 38 Update: libreswan-4.10-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| abnormal TS payload causes pluto daemon to restart in libreswan 4.9 · Issue #954 · libreswan/libreswan · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: libreswan-4.10-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: libreswan-4.10-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: libreswan-4.10-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160643 Oracle Enterprise Linux Security Update for libreswan (ELSA-2023-2633)
- 160689 Oracle Enterprise Linux Security Update for libreswan (ELSA-2023-3095)
- 181672 Debian Security Update for libreswan (DSA 5368-1)
- 184007 Debian Security Update for libreswan (CVE-2023-23009)
- 241450 Red Hat Update for libreswan (RHSA-2023:2633)
- 241491 Red Hat Update for libreswan (RHSA-2023:3095)
- 283931 Fedora Security Update for libreswan (FEDORA-2023-42ec148952)
- 284170 Fedora Security Update for libreswan (FEDORA-2023-a2348480cb)
- 502880 Alpine Linux Security Update for libreswan
- 941048 AlmaLinux Security Update for libreswan (ALSA-2023:2633)
- 941110 AlmaLinux Security Update for libreswan (ALSA-2023:3095)