strongSwan IETF Attribute or Identification Parsing Multiple Remote Code Execution Vulnerabilities
BID:42444
Info
strongSwan IETF Attribute or Identification Parsing Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 42444 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-2628 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2010 12:00AM |
| Updated: | Aug 17 2010 07:54PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 strongSwan strongSwan 4.3.3 S.u.S.E. openSUSE 11.3 S.u.S.E. openSUSE 11.2 |
| Not Vulnerable: |
strongSwan strongSwan 4.4.1 strongSwan strongSwan 4.3.7 |
Discussion
strongSwan IETF Attribute or Identification Parsing Multiple Remote Code Execution Vulnerabilities
strongSwan is prone to multiple remote code-execution vulnerabilities because it uses the 'snprintf()' function in an insecure manner.
Attackers can leverage these issues to execute arbitrary code in the context of the application. Failed attacks will likely result in denial-of-service conditions. Successful attacks will completely compromise the affected computer.
These issues were introduced in strongSwan 4.3.3, and fixed in strongSwan 4.3.7 and 4.4.1.
strongSwan is prone to multiple remote code-execution vulnerabilities because it uses the 'snprintf()' function in an insecure manner.
Attackers can leverage these issues to execute arbitrary code in the context of the application. Failed attacks will likely result in denial-of-service conditions. Successful attacks will completely compromise the affected computer.
These issues were introduced in strongSwan 4.3.3, and fixed in strongSwan 4.3.7 and 4.4.1.
References
strongSwan IETF Attribute or Identification Parsing Multiple Remote Code Execution Vulnerabilities
References:
References:
- [strongSwan] ANNOUNCE: strongswan-4.4.1 released (Andreas Steffen)
- strongSwan Homepage (strongSwan)