Openswan 'XAUTH' Remote Buffer Overflow and Command Injection Vulnerabilities
BID:43588
Info
Openswan 'XAUTH' Remote Buffer Overflow and Command Injection Vulnerabilities
| Bugtraq ID: | 43588 |
| Class: | Unknown |
| CVE: |
CVE-2010-3302 CVE-2010-3308 CVE-2010-3752 CVE-2010-3753 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2010 12:00AM |
| Updated: | Apr 13 2015 08:55PM |
| Credit: | D. Hugh Redelmeier and Paul Wouters. |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Openswan Openswan 2.6.28 Openswan Openswan 2.6.27 Openswan Openswan 2.6.26 Openswan Openswan 2.6.25 |
| Not Vulnerable: |
Openswan Openswan 2.6.29 |
Discussion
Openswan 'XAUTH' Remote Buffer Overflow and Command Injection Vulnerabilities
Openswan is prone to remote buffer-overflow and command-injection vulnerabilities when it connects to a
malicious Cisco compatible gateway using 'XAUTH'.
An attacker can exploit the buffer-overflow issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
The attacker can exploit the remote command-injection issue to execute arbitrary shell commands in the context of the webserver hosting the vulnerable application. This may facilitate the remote compromise of affected computers.
Openswan versions 2.6.25 to 2.6.28 are affected.
Openswan is prone to remote buffer-overflow and command-injection vulnerabilities when it connects to a
malicious Cisco compatible gateway using 'XAUTH'.
An attacker can exploit the buffer-overflow issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
The attacker can exploit the remote command-injection issue to execute arbitrary shell commands in the context of the webserver hosting the vulnerable application. This may facilitate the remote compromise of affected computers.
Openswan versions 2.6.25 to 2.6.28 are affected.
Exploit / POC
Openswan 'XAUTH' Remote Buffer Overflow and Command Injection Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Openswan 'XAUTH' Remote Buffer Overflow and Command Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Openswan 'XAUTH' Remote Buffer Overflow and Command Injection Vulnerabilities
References:
References: