{"id":"CVE-2020-1763","details":"An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash.","modified":"2026-07-08T19:01:39.270751Z","published":"2020-05-12T14:15:12.580Z","references":[{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202007-21"},{"type":"ADVISORY","url":"https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04"},{"type":"ADVISORY","url":"https://www.debian.org/security/2020/dsa-4684"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1813329"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1763"},{"type":"FIX","url":"https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8"},{"type":"FIX","url":"https://libreswan.org/security/CVE-2020-1763/CVE-2020-1763.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libreswan/libreswan","events":[{"introduced":"9b1394ea1190b38005e89a4d5188ba9d63506d0a"},{"last_affected":"f54f585809424a075a364c1266e131395685997c"},{"introduced":"aba60a4fcc11765ecd2fb9352427c722a704bd8a"},{"last_affected":"aba60a4fcc11765ecd2fb9352427c722a704bd8a"},{"fixed":"471a3e41a449d7c753bc4edbba4239501bb62ba8"}],"database_specific":{"cpe":["cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*","cpe:2.3:a:libreswan:libreswan:3.5:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.27"},{"last_affected":"3.31"},{"introduced":"3.5"},{"last_affected":"3.5"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["3.5","v3.31","v3.30","v3.28","v3.27","v3.5"],"database_specific":{"vanir_signatures_modified":"2026-07-08T19:01:39Z","vanir_signatures":[{"source":"https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8","target":{"file":"programs/pluto/ikev1.c"},"deprecated":false,"digest":{"line_hashes":["192785595241567337803171226975667384092","151688309535239392845873598075242329199","267668679704350220890171108057600248734","320866523120216577581671520102311072700"],"threshold":0.9},"id":"CVE-2020-1763-35f05910","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/libreswan/libreswan/commit/471a3e41a449d7c753bc4edbba4239501bb62ba8","target":{"file":"programs/pluto/ikev1.c","function":"process_packet_tail"},"deprecated":false,"digest":{"function_hash":"249042612403858674025323106804503298179","length":9557},"id":"CVE-2020-1763-7142646b","signature_type":"Function"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1763.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}