Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22949
HistoryApr 07, 2020 - 12:43 a.m.

Denial Of Service (DoS)

2020-04-0700:43:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.005 Low

EPSS

Percentile

75.4%

Libreswan is vulnerable to denial of services (DoS). The attack is due to lack of proper handling of memory, causing a NULL pointer dereference by initiating an IKEv2 IKE_SA_INIT exchange, followed by a bogus INFORMATIONAL exchange instead of the normallly expected IKE_AUTH exchange.

References