← Volver a CVEs
CVE-2020-1763
HIGH7.5
Descripcion
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.
Detalles CVE
Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado5/12/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
libreswan:libreswan
Debilidades (CWE)
CWE-125CWE-125
Referencias
https://bugzilla.redhat.com/show_bug.cgi?id=1813329(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1763(secalert@redhat.com)
https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf(secalert@redhat.com)
https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8(secalert@redhat.com)
https://libreswan.org/security/CVE-2020-1763/CVE-2020-1763.txt(secalert@redhat.com)
https://security.gentoo.org/glsa/202007-21(secalert@redhat.com)
https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04(secalert@redhat.com)
https://www.debian.org/security/2020/dsa-4684(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=1813329(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1763(af854a3a-2127-422b-91ae-364da2661108)
https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8(af854a3a-2127-422b-91ae-364da2661108)
https://libreswan.org/security/CVE-2020-1763/CVE-2020-1763.txt(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202007-21(af854a3a-2127-422b-91ae-364da2661108)
https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2020/dsa-4684(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.