Vulnerability Name: | CVE-2020-1763 (CCN-181901) | ||||||||||||||||||
Assigned: | 2019-11-27 | ||||||||||||||||||
Published: | 2020-05-11 | ||||||||||||||||||
Updated: | 2021-05-05 | ||||||||||||||||||
Summary: | An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash. | ||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-1763 Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1813329 Source: CCN Type: Red Hat Bugzilla Bug 1814541 CVE-2020-1763 libreswan: DoS attack via malicious IKEv1 informational exchange message Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1763 Source: CONFIRM Type: Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf Source: XF Type: UNKNOWN libreswan-cve20201763-dos(181901) Source: CCN Type: libreswan GIT Repository security: Fix for CVE-2020-1763 Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8 Source: CONFIRM Type: Patch, Vendor Advisory https://libreswan.org/security/CVE-2020-1763/CVE-2020-1763.txt Source: GENTOO Type: Third Party Advisory GLSA-202007-21 Source: MISC Type: Third Party Advisory, US Government Resource https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04 Source: DEBIAN Type: Third Party Advisory DSA-4684 Source: CCN Type: IBM Security Bulletin 6257769 (Netezza Host Management) Publicly disclosed vulnerability from Libreswan affects IBM Netezza Host Management | ||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |