Null pointer dereference in Openswan - CVE-2013-6466

 

Null pointer dereference in Openswan - CVE-2013-6466

Published: September 8, 2017


Vulnerability identifier: #VU8168
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2013-6466
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: openswan.org
Affected software:
Openswan

Detailed vulnerability description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to NULL pointer dereference when handling malicious input. A remote attacker can supply specially crafted IKEv2 packets that lack expected payloads and cause IKE daemon to restart.

Successful exploitation of the vulnerability results in denial of service.

How to mitigate CVE-2013-6466

Update to version 2.6.40.

Sources