CVE-2015-3240
Published: 9 November 2015
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
Notes
Author | Note |
---|---|
sbeattie | affects openswan if compiled with NSS |
Priority
Status
Package | Release | Status |
---|---|---|
libreswan Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(3.19-1)
|
bionic |
Not vulnerable
(3.19-1)
|
|
cosmic |
Not vulnerable
(3.19-1)
|
|
disco |
Not vulnerable
(3.19-1)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(3.15)
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Not vulnerable
(3.19-1)
|
|
Patches: upstream: https://libreswan.org/security/CVE-2015-3240/libreswan-3.14-cve-2015-3240-dhshared.patch.asc |
||
openswan Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
precise |
Ignored
(end of life)
|
|
trusty |
Does not exist
(trusty was needed)
|
|
upstream |
Released
(2.6.45)
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|