Openswan IKE Packet NULL Pointer Dereference Remote Denial Of Service Vulnerability
BID:49984
Info
Openswan IKE Packet NULL Pointer Dereference Remote Denial Of Service Vulnerability
| Bugtraq ID: | 49984 |
| Class: | Unknown |
| CVE: |
CVE-2011-3380 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2011 12:00AM |
| Updated: | May 07 2015 05:13PM |
| Credit: | Paul Wouters |
| Vulnerable: |
Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6 Openswan Openswan 2.6.35 Openswan Openswan 2.6.33 Openswan Openswan 2.6.29 |
| Not Vulnerable: |
Openswan Openswan 2.6.36 |
Discussion
Openswan IKE Packet NULL Pointer Dereference Remote Denial Of Service Vulnerability
Openswan is prone to a remote denial-of-service vulnerability due to a NULL-pointer dereference condition.
An attacker may exploit this issue to crash the application, resulting in a denial-of-service condition.
Openswan 2.6.29 to 2.6.35 are vulnerable.
Openswan is prone to a remote denial-of-service vulnerability due to a NULL-pointer dereference condition.
An attacker may exploit this issue to crash the application, resulting in a denial-of-service condition.
Openswan 2.6.29 to 2.6.35 are vulnerable.
Exploit / POC
Openswan IKE Packet NULL Pointer Dereference Remote Denial Of Service Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Openswan IKE Packet NULL Pointer Dereference Remote Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Openswan IKE Packet NULL Pointer Dereference Remote Denial Of Service Vulnerability
References:
References:
- Bug 742065 - (CVE-2011-3380) CVE-2011-3380 openswan: IKE invalid key length allo (Red Hat Bugzilla)
- Openswan Homepage (Openswan)