发布时间: 2024年3月29日
修改时间: 2024年4月12日
The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.
NVD | openEuler | |
---|---|---|
CVSS评分 | 3.5 | |
Attack Vector | Adjacent | |
Attack Complexity | Low | |
Privileges Required | Low | |
User Interaction | None | |
Scope | Unchanged | |
Confidentiality | None | |
Integrity | None | |
Availability | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-1526 | libreswan security update | 2024年4月12日 |
KylinSec-SA-2024-3161 | libreswan security update | 2024年3月29日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | libreswan | Fixed |
KY3.4-5A | libreswan | Fixed |
KY3.5.1 | libreswan | Fixed |
KY3.5.2 | libreswan | Fixed |