Description
An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr payload with ID_FQDN, a NULL pointer dereference causes a crash and restart of the pluto daemon. NOTE: the earliest affected version is 4.6.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42486 | An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr payload with ID_FQDN, a NULL pointer dereference causes a crash and restart of the pluto daemon. NOTE: the earliest affected version is 4.6. |
References
History
Thu, 13 Feb 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift
Redhat rhel Eus |
|
| CPEs | cpe:/a:redhat:openshift:4.15::el9 cpe:/a:redhat:openshift:4.16::el9 cpe:/a:redhat:openshift:4.17::el9 cpe:/a:redhat:rhel_eus:9.2 |
|
| Vendors & Products |
Redhat openshift
Redhat rhel Eus |
Mon, 02 Dec 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel E4s
|
|
| CPEs | cpe:/a:redhat:rhel_e4s:9.0 | |
| Vendors & Products |
Redhat rhel E4s
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T17:46:56.601Z
Reserved: 2023-07-24T00:00:00.000Z
Link: CVE-2023-38711
Updated: 2024-08-02T17:46:56.601Z
Status : Modified
Published: 2023-08-25T21:15:08.230
Modified: 2024-11-21T08:14:06.280
Link: CVE-2023-38711
OpenCVE Enrichment
No data.
Weaknesses
EUVD