CVE-2014-2891Strongswan vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.6%
top 18.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7
Latest updateMay 14

Description

strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

debiandebian/strongswan< strongswan 5.1.2-1 (bookworm)
Debianstrongswan/strongswan< 5.1.2-1+3

🔴Vulnerability Details

2
GHSA
GHSA-r42j-m8hf-cm2r: strongSwan before 52022-05-14
OSV
CVE-2014-2891: strongSwan before 52014-05-07

📋Vendor Advisories

2
Red Hat
strongswan: denial of service via crafted ID_DER_ASN1_DN_ID payload2014-05-05
Debian
CVE-2014-2891: strongswan - strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NU...2014

💬Community

1
Bugzilla
CVE-2014-2891 strongswan: denial of service via crafted ID_DER_ASN1_DN_ID payload2014-05-07