CVE Database
/

CVE-2011-3380

Back to search

CVE-2011-3380

Published: Nov 17, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.

VendorProductVersions

n/a

n/a

affected
n/a

References

46306
third-party-advisory
x_refsource_SECUNIA
RHSA-2011:1356
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now