5
CVSSv2

CVE-2011-3380

Published: 17/11/2011 Updated: 29/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Openswan 2.6.29 up to and including 2.6.35 allows remote malicious users to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.

Vulnerable Product Search on Vulmon Subscribe to Product

xelerance openswan 2.6.34

xelerance openswan 2.6.35

xelerance openswan 2.6.29

xelerance openswan 2.6.32

xelerance openswan 2.6.33

xelerance openswan 2.6.30

xelerance openswan 2.6.31

Vendor Advisories

A NULL pointer dereference flaw was found in the way Openswan's pluto IKE daemon handled certain error conditions A remote, unauthenticated attacker could send a specially-crafted IKE packet that would crash the pluto daemon ...