在 FIPS 模式下,Libreswan 的 函数会调用 ,并断言(assert)其返回值不为 NULL。然而,当公钥提取失败时(例如,当 RSA 指数被设置为 0 时), 会返回 NULL。 远程攻击者可以通过在 CERT 载荷(payload)中发送一个格式错误的 X.509 证书来触发该断言失败,从而导致 pluto 守护进程中断并重启。持续利用此漏洞可导致拒绝服务(DoS)。该漏洞无法实现远程代码执行。 IKEv1 和 IKEv2 均受影响。 该漏洞仅在以下条件下可被利用: 1. 操作系统和 Libresw
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Libreswan Project | libreswan | 3.0 ~ 5.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet