An issue was discovered in Libreswan 3.x and 4.x before 4...
Moderate severity
Unreviewed
Published
Aug 25, 2023
to the GitHub Advisory Database
•
Updated Dec 20, 2023
Description
Published by the National Vulnerability Database
Aug 25, 2023
Published to the GitHub Advisory Database
Aug 25, 2023
Last updated
Dec 20, 2023
An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.
References