SB2014041721 - Input validation error in openswan (Alpine package)
Published: April 17, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2014-2037)
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=f61b6c8609c53376958880ab2a1741f6888859a4
- https://git.alpinelinux.org/aports/commit/?id=95c7f93375ff9e15f0ccd68ff25ae08f230dec98
- https://git.alpinelinux.org/aports/commit/?id=1df893d29e73824172978ca87bc5575b1fcace34
- https://git.alpinelinux.org/aports/commit/?id=59f82a99051677a0a8ffbd33585293f529cf627c