The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.
2019-06-12T14:29:02.917
2024-11-21T04:18:32.000
Modified
CVSSv3.1: 3.1 (LOW)
AV:N/AC:M/Au:S/C:N/I:N/A:P
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | libreswan | libreswan | < 3.29 | Yes |
Application | strongswan | strongswan | < 5.0.0 | Yes |
Application | xelerance | openswan | * | Yes |
Operating System | fedoraproject | fedora | 29 | Yes |
Operating System | fedoraproject | fedora | 30 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |