5
CVSSv2

CVE-2014-9221

Published: 07/01/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

strongSwan 4.5.x up to and including 5.2.x prior to 5.2.1 allows remote malicious users to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.

Vulnerable Product Search on Vulmon Subscribe to Product

strongswan strongswan 5.1.2

strongswan strongswan 4.5.3

strongswan strongswan 4.5.2

strongswan strongswan 5.0.1

strongswan strongswan 5.1.0

strongswan strongswan 4.5.1

strongswan strongswan 5.2.0

strongswan strongswan 5.1.3

strongswan strongswan 4.6.4

strongswan strongswan 4.6.2

strongswan strongswan 5.1.1

strongswan strongswan 5.0.3

strongswan strongswan 5.0.4

strongswan strongswan 4.6.1

strongswan strongswan 5.0.2

strongswan strongswan 4.6.0

strongswan strongswan 4.6.3

strongswan strongswan 5.0.0

strongswan strongswan 4.5.0

opensuse opensuse 13.1

opensuse opensuse 13.2

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

fedoraproject fedora 21

debian debian linux 7.0

Vendor Advisories

strongSwan could be made to crash if it received specially crafted network traffic ...
strongSwan 45x through 52x before 521 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025 ...