← Back

Libreswan

libreswan

24 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Libreswan
libreswan

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libreswan
1Libreswan
Apr 29, 2026
Jan 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
1Libreswan
1Libreswan
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack vectors, involving the /var/tmp/libreswan-nss-pwd temporary file.
1Libreswan
1Libreswan
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet.
1Libreswan
1Libreswan
Apr 29, 2026
Jul 9, 2013
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and pos...Show more
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.Show less