CVE-2014-2338
Publication date 16 April 2014
Last updated 24 July 2024
Ubuntu priority
Description
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| strongswan | ||
| 16.04 LTS xenial |
Fixed 5.1.2-0ubuntu2
|
|
| 14.04 LTS trusty |
Fixed 5.1.2-0ubuntu2
|
|