Bug 1054022 (CVE-2013-7294) - CVE-2013-7294 libreswan: DoS via an IKEv2 I1 notification
Summary: CVE-2013-7294 libreswan: DoS via an IKEv2 I1 notification
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2013-7294
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1054024
Blocks: 1054025
TreeView+ depends on / blocked
 
Reported: 2014-01-16 06:00 UTC by Ratul Gupta
Modified: 2019-09-29 13:12 UTC (History)
3 users (show)

Fixed In Version: libreswan 3.7
Clone Of:
Environment:
Last Closed: 2015-02-19 21:42:56 UTC
Embargoed:


Attachments (Terms of Use)

Description Ratul Gupta 2014-01-16 06:00:28 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-7294 to the following vulnerability:

Name: CVE-2013-7294
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7294
Assigned: 20140115
Reference: https://lists.libreswan.org/pipermail/swan-announce/2013/000007.html
Reference: https://github.com/libreswan/libreswan/commit/2899351224fe2940aec37d7656e1e392c0fe07f0
Reference: OSVDB:101573
Reference: http://www.osvdb.org/101573
Reference: SECUNIA:56276
Reference: http://secunia.com/advisories/56276

The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.

Comment 3 Paul Wouters 2014-01-17 19:52:58 UTC
who created this CVE number? It is wrong.

This is covered in CVE-2013-6467. The openswan CVE for this is CVE-2013-6466

See: https://libreswan.org/security/CVE-2013-6467/CVE-2013-6467.txt

Comment 4 Paul Wouters 2014-01-17 19:56:29 UTC
sorry my bad. this is referring to the _previous_ CVE.

While openswan had the same bug, it could not cause a problem because of a size of IKE packet versus described length check. in libreswan 3.7, this check has more conditionals due to an added ike padding feature, and thus exposing the vulnerable code in some cases. So there is no openswan CVE for libreswan  CVE-2013-7294

Comment 7 Kurt Seifried 2015-02-19 21:42:56 UTC
This was addressed in the release of RHEL 7.


Note You need to log in before you can comment on or make changes to this bug.