« Volver al listado

CVE-2011-3380

Estado: ModificadaMedia (5)—

Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-3380",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-11-17T19:55:01.127",
  "references": [
    {
      "url": "http://secunia.com/advisories/46306",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openswan.org/download/CVE-2011-3380/CVE-2011-3380.txt",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-1356.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/46306",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openswan.org/download/CVE-2011-3380/CVE-2011-3380.txt",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-1356.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function."
    },
    {
      "lang": "es",
      "value": "Openswan v2.6.29 a través de v2.6.35 permite a atacantes remotos provocar una denegación de servicio (puntero a NULL y Plutón accidente demonio IKE) a través de un mensaje ISAKMP con un atributo no válido key_length, que no se gestiona adecuadamente por la función de control de errores."
    }
  ],
  "lastModified": "2026-06-16T23:33:11.437",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xelerance:openswan:2.6.29:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFAFF39D-126F-4984-A40B-88E94C680141"
            },
            {
              "criteria": "cpe:2.3:a:xelerance:openswan:2.6.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73EE725B-C26E-4343-B5F2-F5DF31A197C1"
            },
            {
              "criteria": "cpe:2.3:a:xelerance:openswan:2.6.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A26D9508-E43D-4BA2-9734-CDABBD405D26"
            },
            {
              "criteria": "cpe:2.3:a:xelerance:openswan:2.6.32:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01D11526-6DCD-4B73-BACC-FC619D92BBB5"
            },
            {
              "criteria": "cpe:2.3:a:xelerance:openswan:2.6.33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24641D2D-BB95-4E26-AD96-8CE96B6B3976"
            },
            {
              "criteria": "cpe:2.3:a:xelerance:openswan:2.6.34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A24A87F0-AE9A-46DB-8E47-7819E18513CE"
            },
            {
              "criteria": "cpe:2.3:a:xelerance:openswan:2.6.35:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13460979-98A3-4873-B9E4-86327F9C2B2A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/476.html\r\n\r\n'CWE-476: NULL Pointer Dereference'",
  "sourceIdentifier": "secalert@redhat.com"
}