CVE-2013-6076Strongswan vulnerability

7 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
0.4%
top 39.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 2
Latest updateMay 17

Description

strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted IKEv1 fragmentation packet.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/strongswan< strongswan 5.1.0-3 (bookworm)
Debianstrongswan/strongswan< 5.1.0-3+3
NVDstrongswan/strongswan4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-499g-gpw8-wmq3: strongSwan 52022-05-17
OSV
CVE-2013-6076: strongSwan 52013-11-02

📋Vendor Advisories

2
Red Hat
strongswan: denial of service when handling IKEv1 fragmentation payloads2013-11-01
Debian
CVE-2013-6076: strongswan - strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of serv...2013

💬Community

2
Bugzilla
CVE-2013-6076 strongswan: denial of service when handling IKEv1 fragmentation payloads [epel-6]2013-11-04
Bugzilla
CVE-2013-6076 strongswan: denial of service when handling IKEv1 fragmentation payloads2013-11-04