Vulnerabilities > Libreswan > Libreswan > 3.1

DATE CVE VULNERABILITY TITLE RISK
2023-08-25 CVE-2023-38712 NULL Pointer Dereference vulnerability in Libreswan
An issue was discovered in Libreswan 3.x and 4.x before 4.12.
network
low complexity
libreswan CWE-476
6.5
2019-06-12 CVE-2019-10155 Improper Validation of Integrity Check Value vulnerability in multiple products
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified.
3.1
2019-05-24 CVE-2019-12312 Reachable Assertion vulnerability in Libreswan
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.
network
low complexity
libreswan CWE-617
5.0
2017-06-13 CVE-2016-5391 NULL Pointer Dereference vulnerability in multiple products
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
network
low complexity
libreswan fedoraproject CWE-476
7.5
2016-06-16 CVE-2016-5361 Improper Input Validation vulnerability in Libreswan
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed UDP packet.
network
low complexity
libreswan CWE-20
5.0
2014-01-26 CVE-2013-6467 Remote Denial of Service vulnerability in Libreswan 'IKEv2' Payloads
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
network
low complexity
libreswan
5.0
2014-01-16 CVE-2013-7294 Improper Input Validation vulnerability in Libreswan
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
network
low complexity
libreswan CWE-20
5.0
2013-07-09 CVE-2013-2052 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Libreswan 3.0/3.1
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.
network
high complexity
libreswan CWE-119
5.1