Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://secunia.com/advisories/56276 | third party advisory vendor advisory |
https://lists.libreswan.org/pipermail/swan-announce/2013/000007.html | mailing list patch vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124928.html | vendor advisory |
https://libreswan.org/security/CVE-2013-4564/CVE-2013-4564.txt.asc | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124943.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124911.html | vendor advisory |