Input validation error in Openswan - CVE-2014-2037
Published: November 26, 2014 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
Affected software
openswan (Alpine package)
How to mitigate CVE-2014-2037
openswan (Alpine package) - update to 2.6.41-r0