CVE-2022-23094
15.01.2022, 02:15
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.Enginsight
Vendor | Product | Version |
---|---|---|
libreswan | libreswan | 4.2 ≤ 𝑥 < 4.6 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References