Unrated severityNVD Advisory· Published Nov 9, 2015· Updated May 6, 2026
CVE-2015-3240
CVE-2015-3240
Description
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- libreswan.org/security/CVE-2015-3240/CVE-2015-3240.txtnvdVendor Advisory
- lists.openswan.org/pipermail/users/2015-August/023401.htmlnvdVendor Advisory
- rhn.redhat.com/errata/RHSA-2015-1979.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlnvd
- www.securityfocus.com/bid/77536nvd
- www.securitytracker.com/id/1033418nvd
- security.gentoo.org/glsa/201603-13nvd
News mentions
0No linked articles in our index yet.