CVE-2020-1763

Source
https://cve.org/CVERecord?id=CVE-2020-1763
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1763.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-1763
Downstream
Published
2020-05-12T14:15:12.580Z
Modified
2026-07-08T19:01:39.270751Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.

References

Affected packages

Git / github.com/libreswan/libreswan

Affected ranges

Type
GIT
Repo
https://github.com/libreswan/libreswan
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:libreswan:libreswan:3.5:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "3.27"
        },
        {
            "last_affected": "3.31"
        },
        {
            "introduced": "3.5"
        },
        {
            "last_affected": "3.5"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.5
v3.*
v3.27
v3.28
v3.30
v3.31
v3.5

Database specific

vanir_signatures_modified
"2026-07-08T19:01:39Z"
vanir_signatures
[
    {
        "target": {
            "file": "programs/pluto/ikev1.c"
        },
        "id": "CVE-2020-1763-35f05910",
        "digest": {
            "line_hashes": [
                "192785595241567337803171226975667384092",
                "151688309535239392845873598075242329199",
                "267668679704350220890171108057600248734",
                "320866523120216577581671520102311072700"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8"
    },
    {
        "target": {
            "function": "process_packet_tail",
            "file": "programs/pluto/ikev1.c"
        },
        "id": "CVE-2020-1763-7142646b",
        "digest": {
            "function_hash": "249042612403858674025323106804503298179",
            "length": 9557.0
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1763.json"