Updated libreswan packages fix security vulnerability
Publication date: 15 May 2020Modification date: 15 May 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-1763
Description
Updated libreswan packages fix security vulnerability: An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan. An unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash (CVE-2020-1763).
References
SRPMS
7/core
- libreswan-3.32-1.mga7