Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38712


An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.


Published

2023-08-25T21:15:08.293

Last Modified

2024-11-21T08:14:06.427

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application libreswan libreswan < 4.0 Yes
Application libreswan libreswan < 4.12 Yes

References