CVE-2020-1763 PUBLISHED

An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.

EPSS 4.76% · 89.4th percentile

Risk Scores

EPSS Score
4.76%
89.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibreswan0, 3.20-7build1, 3.21-2
Ubuntu:20.04:LTSlibreswan0, 3.29-2, 3.29-2build1

Timeline

References

Open in Interactive Console →