Advisories ยป MGASA-2022-0030

Updated libreswan packages fix security vulnerability

Publication date: 25 Jan 2022
Modification date: 25 Jan 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-23094

Description

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of
service (NULL pointer dereference and daemon crash) via a crafted IKEv1
packet because pluto/ikev1.c wrongly expects that a state object exists.
(CVE-2022-23094)
                

References

SRPMS

8/core