Vulnerability Details CVE-2011-3380
Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.5%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2011-3380
-
cpe:2.3:a:xelerance:openswan:2.6.29
-
cpe:2.3:a:xelerance:openswan:2.6.30
-
cpe:2.3:a:xelerance:openswan:2.6.31
-
cpe:2.3:a:xelerance:openswan:2.6.32
-
cpe:2.3:a:xelerance:openswan:2.6.33
-
cpe:2.3:a:xelerance:openswan:2.6.34
-
cpe:2.3:a:xelerance:openswan:2.6.35