Bugzilla – Bug 847509
VUL-0: CVE-2013-6076: strongswan remote DoS
Last modified: 2014-01-14 08:35:38 UTC
CVE-2013-6076 The bug can be triggered by a crafted IKEv1 fragmentation payload and is caused by a NULL pointer dereference. If the daemon has any IKEv1 or mixed connections configured, a crafted payload can result in a crash of the IKE daemon. Using the flaw for attacks other than DoS, such as code injection, is not possible.
Affected are strongSwan versions 5.0.2 and newer. CRD is November 1st, 1200 UTC
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (847509) was mentioned in https://build.opensuse.org/request/show/205541 Factory / strongswan
is public http://www.strongswan.org/blog/2013/11/01/strongswan-denial-of-service-vulnerability-%28cve-2013-6076%29.html
also in 13.1. 12.3 has 5.0.1, so is not affected.