#VU88534 Reachable assertion in libreswan - CVE-2024-3652
Published: April 15, 2024 / Updated: April 23, 2024
libreswan
libreswan.org
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion within the compute_proto_keymat() function when handling IKEv1 packets within the default AH/ESP responder. A remote authenticated user can send specially crafted packets to the server and perform a denial of service (DoS) attack.