Total vulnerabilities in the database
Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.
Software | From | Fixed in |
---|---|---|
xelerance / openswan | 2.6.29 | 2.6.29.x |
xelerance / openswan | 2.6.30 | 2.6.30.x |
xelerance / openswan | 2.6.31 | 2.6.31.x |
xelerance / openswan | 2.6.32 | 2.6.32.x |
xelerance / openswan | 2.6.33 | 2.6.33.x |
xelerance / openswan | 2.6.34 | 2.6.34.x |
xelerance / openswan | 2.6.35 | 2.6.35.x |