CVE-2016-5391
HIGHlibreswan < 3.18 - Denial of Service via NULL Pointer Dereference
Title source: llmDescription
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
References (4)
Core 4
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/65R6OA5AY7K2UBQUDOLOS5Y3SCULQI6I/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKMS7R4TG6LTAGEBOWVUXF6LAWQXLNXV/
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1356183
Patch, Vendor Advisory x_refsource_confirm
https://libreswan.org/security/CVE-2016-5391/CVE-2016-5391.txt
Scores
CVSS v3
7.5
EPSS
0.0301
EPSS Percentile
85.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (3)
fedoraproject/fedora
23
fedoraproject/fedora
24
libreswan/libreswan
< 3.17
Published
Jun 13, 2017
Tracked Since
Feb 18, 2026