Updated libreswan packages fix security vulnerability
Publication date: 25 Jan 2022Modification date: 25 Jan 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-23094
Description
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. (CVE-2022-23094)
References
SRPMS
8/core
- libreswan-4.6-4.mga8