5
CVSSv2

CVE-2014-2891

Published: 07/05/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

strongSwan prior to 5.1.2 allows remote malicious users to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.

Vulnerable Product Search on Vulmon Subscribe to Product

debian strongswan

strongswan strongswan 5.0.1

strongswan strongswan 5.1.0

strongswan strongswan 5.0.3

strongswan strongswan 5.0.4

strongswan strongswan 5.0.2

strongswan strongswan

strongswan strongswan 5.0.0

Vendor Advisories

A vulnerability has been found in the ASN1 parser of strongSwan, an IKE/IPsec suite used to establish IPsec protected links By sending a crafted ID_DER_ASN1_DN ID payload to a vulnerable pluto or charon daemon, a malicious remote user can provoke a null pointer dereference in the daemon parsing the identity, leading to a crash and a denial of ser ...
strongSwan before 512 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload ...