Vulnerability Description
Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libreswan | Libreswan | 3.6 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124911.h
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124928.h
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124943.h
- http://secunia.com/advisories/56276Vendor Advisory
- https://libreswan.org/security/CVE-2013-4564/CVE-2013-4564.txt.ascVendor Advisory
- https://lists.libreswan.org/pipermail/swan-announce/2013/000007.htmlPatchVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124911.h
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124928.h
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124943.h
- http://secunia.com/advisories/56276Vendor Advisory
- https://libreswan.org/security/CVE-2013-4564/CVE-2013-4564.txt.ascVendor Advisory
- https://lists.libreswan.org/pipermail/swan-announce/2013/000007.htmlPatchVendor Advisory
FAQ
What is CVE-2013-4564?
CVE-2013-4564 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet.
How severe is CVE-2013-4564?
CVE-2013-4564 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4564?
Check the references section above for vendor advisories and patch information. Affected products include: Libreswan Libreswan.