CVE-2011-3380
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2011
Last modified:
11/04/2025
Description
Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:xelerance:openswan:2.6.29:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xelerance:openswan:2.6.30:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xelerance:openswan:2.6.31:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xelerance:openswan:2.6.32:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xelerance:openswan:2.6.33:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xelerance:openswan:2.6.34:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xelerance:openswan:2.6.35:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/46306
- http://www.openswan.org/download/CVE-2011-3380/CVE-2011-3380.txt
- http://www.redhat.com/support/errata/RHSA-2011-1356.html
- http://secunia.com/advisories/46306
- http://www.openswan.org/download/CVE-2011-3380/CVE-2011-3380.txt
- http://www.redhat.com/support/errata/RHSA-2011-1356.html



