Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-11-17 11:55
Updated : 2019-07-29 06:26
NVD link : CVE-2011-3380
Mitre link : CVE-2011-3380
JSON object : View
CWE
Products Affected
xelerance
- openswan