CVE-2019-10155
12.06.2019, 14:29
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libreswan | libreswan | 𝑥 < 3.29 |
| strongswan | strongswan | 𝑥 < 5.0.0 |
| xelerance | openswan | * |
| redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libreswan |
| ||||||||||||
| strongswan |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libreswan |
|
References