CVE-2011-3380
17.11.2011, 19:55
Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.Enginsight
Vendor | Product | Version |
---|---|---|
xelerance | openswan | 2.6.29 |
xelerance | openswan | 2.6.30 |
xelerance | openswan | 2.6.31 |
xelerance | openswan | 2.6.32 |
xelerance | openswan | 2.6.33 |
xelerance | openswan | 2.6.34 |
xelerance | openswan | 2.6.35 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References