CVE-2014-2891
published 2014-05-07CVE-2014-2891: strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.51%
83.0th percentile
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | strongswan | < strongswan 5.1.2-1 (bookworm) | strongswan 5.1.2-1 (bookworm) |
| debian | strongswan | <= 5.1.2 | — |
| strongswan | strongswan | <= 5.1.1 | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | >= 0 < 5.1.2-1 | 5.1.2-1 |
| strongswan | strongswan | >= 0 < 5.1.2-1 | 5.1.2-1 |
| strongswan | strongswan | >= 0 < 5.1.2-1 | 5.1.2-1 |
| strongswan | strongswan | >= 0 < 5.1.2-1 | 5.1.2-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r42j-m8hf-cm2r: strongSwan before 5
ghsa_unreviewed·2022-05-14
CVE-2014-2891 [MEDIUM] GHSA-r42j-m8hf-cm2r: strongSwan before 5
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.
OSV
CVE-2014-2891: strongSwan before 5
osv·2014-05-07·CVSS 5.0
CVE-2014-2891 [MEDIUM] CVE-2014-2891: strongSwan before 5
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.
Red Hat
strongswan: denial of service via crafted ID_DER_ASN1_DN_ID payload
vendor_redhat·2014-05-05·CVSS 5.0
CVE-2014-2891 [MEDIUM] strongswan: denial of service via crafted ID_DER_ASN1_DN_ID payload
strongswan: denial of service via crafted ID_DER_ASN1_DN_ID payload
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.
Statement: Not vulnerable. This issue did not affect the versions of openswan as shipped with Red Hat Enterprise Linux 5 and 6.
Package: openswan (Red Hat Enterprise Linux 5) - Not affected
Package: openswan (Red Hat Enterprise Linux 6) - Not affected
Package: libreswan (Red Hat Enterprise Linux 7) - Not affected
Package: strongimcv (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-2891: strongswan - strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NU...
vendor_debian·2014·CVSS 5.0
CVE-2014-2891 [MEDIUM] CVE-2014-2891: strongswan - strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NU...
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.
Scope: local
bookworm: resolved (fixed in 5.1.2-1)
bullseye: resolved (fixed in 5.1.2-1)
forky: resolved (fixed in 5.1.2-1)
sid: resolved (fixed in 5.1.2-1)
trixie: resolved (fixed in 5.1.2-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2014-05/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00066.htmlhttp://secunia.com/advisories/59864http://www.debian.org/security/2014/dsa-2922http://www.securityfocus.com/bid/67212http://www.strongswan.org/blog/2014/05/05/strongswan-denial-of-service-vulnerability-%28cve-2014-2891%29.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00066.htmlhttp://secunia.com/advisories/59864http://www.debian.org/security/2014/dsa-2922http://www.securityfocus.com/bid/67212http://www.strongswan.org/blog/2014/05/05/strongswan-denial-of-service-vulnerability-%28cve-2014-2891%29.html
2014-05-07
Published