diff options
| author | Tobias Brunner <tobias@strongswan.org> | 2015-05-21 14:56:01 +0200 |
|---|---|---|
| committer | Tobias Brunner <tobias@strongswan.org> | 2016-03-04 16:03:00 +0100 |
| commit | 47701e1178a91da363a61bd0478932352bfde2af (patch) | |
| tree | c7694752dd55cc98f921f42d2492679633b10644 /src/libcharon/plugins/vici/python | |
| parent | fb7cc16d67e867191335bf05ed5c9fc7e3599a14 (diff) | |
| download | strongswan-47701e1178a91da363a61bd0478932352bfde2af.tar.bz2 strongswan-47701e1178a91da363a61bd0478932352bfde2af.tar.xz | |
ike-init: Verify REDIRECT notify before processing IKE_SA_INIT message
An attacker could blindly send a message with invalid nonce data (or none
at all) to DoS an initiator if we just destroy the SA. To prevent this we
ignore the message and wait for the one by the correct responder.
Diffstat (limited to 'src/libcharon/plugins/vici/python')
0 files changed, 0 insertions, 0 deletions
