CVE-2019-10155
12.06.2019, 14:29
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.Enginsight
Vendor | Product | Version |
---|---|---|
libreswan | libreswan | 𝑥 < 3.29 |
strongswan | strongswan | 𝑥 < 5.0.0 |
xelerance | openswan | * |
redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libreswan |
| ||||||||||||
strongswan |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libreswan |
|
References