FreeS/WAN X.509 Patch Certificate Verification Vulnerability

BID:10611

Info

FreeS/WAN X.509 Patch Certificate Verification Vulnerability

Bugtraq ID: 10611
Class: Access Validation Error
CVE: CVE-2004-0590
Remote: Yes
Local: No
Published: Jun 25 2004 12:00AM
Updated: Jul 12 2009 05:16AM
Credit: Discovery of this vulnerability is credited to Thomas Walpuski <[email protected]>.
Vulnerable: Super FreeS/WAN Super FreeS/WAN 1.99.7 .3
strongSwan strongSwan 2.1.3
Openswan Openswan 2.1.2
Openswan Openswan 2.1.1
Openswan Openswan 1.0.5
Openswan Openswan 1.0.4
Gentoo Linux 1.4 _rc3
Gentoo Linux 1.4 _rc2
Gentoo Linux 1.4 _rc1
Gentoo Linux 1.4
FreeS/WAN FreeS/WAN 2.4 -r1
FreeS/WAN FreeS/WAN 1.9.6
- Debian Linux 3.0 sparc
- Debian Linux 3.0 s/390
- Debian Linux 3.0 ppc
- Debian Linux 3.0 mipsel
- Debian Linux 3.0 mips
- Debian Linux 3.0 m68k
- Debian Linux 3.0 ia-64
- Debian Linux 3.0 ia-32
- Debian Linux 3.0 hppa
- Debian Linux 3.0 arm
- Debian Linux 3.0 alpha
FreeS/WAN FreeS/WAN 1.9.5
FreeS/WAN FreeS/WAN 1.9.4
FreeS/WAN FreeS/WAN 1.9.3
FreeS/WAN FreeS/WAN 1.9.2
FreeS/WAN FreeS/WAN 1.9.1
FreeS/WAN FreeS/WAN 1.9
Andreas Steffen x509 patch 1.5.5
Andreas Steffen x509 patch 1.5.4
Andreas Steffen x509 patch 0.9.39
Not Vulnerable: Andreas Steffen x509 patch 1.6.1
+ FreeS/WAN FreeS/WAN 2.4 -r1
+ FreeS/WAN FreeS/WAN 2.0 5
+ FreeS/WAN FreeS/WAN 2.0 4
Andreas Steffen x509 patch 0.9.41
+ FreeS/WAN FreeS/WAN 1.99

Discussion

FreeS/WAN X.509 Patch Certificate Verification Vulnerability

FreeS/WAN X.509 patch is reported susceptible to a certificate verification vulnerability.

When the vulnerable implementation is negotiating an IPSec connection using PKCS#7 wrapped X.509 certificates, it can be fooled into authenticating fake certificates.

If an attacker crafts a Certificate Authority (CA) certificate and a user certificate with identical subjects, they can reportedly be improperly authenticated by FreeS/WAN.

Using this vulnerability, an attacker could potentially successfully authenticate to a FreeS/WAN VPN server. Further attacks on machines now accessible to the attacker are likely possible.

**Update: This vulnerability was previously thought to exist in the FreeS/WAN application, however, new information suggests that the issue is present in the X.509 patch for the application.

Exploit / POC

FreeS/WAN X.509 Patch Certificate Verification Vulnerability

An exploit is not required.

Solution / Fix

FreeS/WAN X.509 Patch Certificate Verification Vulnerability

Solution:
Gentoo has released advisory GLSA 200406-20 to address this issue. Gentoo have advised the following:
All FreeS/WAN 1.9x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv "=net-misc/freeswan-1.99-r1"
# emerge "=net-misc/freeswan-1.99-r1"

All FreeS/WAN 2.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/freeswan-2.04-r1"
# emerge ">=net-misc/freeswan-2.04-r1"

All Openswan 1.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv "=net-misc/openswan-1.0.6_rc1"
# emerge "=net-misc/openswan-1.0.6_rc1"

All Openswan 2.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/openswan-2.1.4"
# emerge ">=net-misc/openswan-2.1.4"

All strongSwan users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/strongswan-2.1.3"
# emerge ">=net-misc/strongswan-2.1.3"

All Super-FreeS/WAN users should migrate to the latest stable version
of Openswan. Note that Portage will force a move for Super-FreeS/WAN
users to Openswan:
# emerge sync
# emerge -pv "=net-misc/openswan-1.0.6_rc1"
# emerge "=net-misc/openswan-1.0.6_rc1"

Mandrake has released an advisory (MDKSA-2004:070) to address this issue. Please see the referenced advisory for more information.

References

FreeS/WAN X.509 Patch Certificate Verification Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report