Openswan Crpyotgraphic Helper Use After Free Remote Denial Of Service Vulnerability
BID:50440
Info
Openswan Crpyotgraphic Helper Use After Free Remote Denial Of Service Vulnerability
| Bugtraq ID: | 50440 |
| Class: | Design Error |
| CVE: |
CVE-2011-4073 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2011 12:00AM |
| Updated: | Apr 13 2015 09:50PM |
| Credit: | ETH Zurich |
| Vulnerable: |
Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Openswan Openswan 2.6.22 Openswan Openswan 2.6.21 Openswan Openswan 2.6.20 Openswan Openswan 2.6.16 Openswan Openswan 2.4.15 Openswan Openswan 2.4.14 Openswan Openswan 2.4.13 Openswan Openswan 2.4.4 Openswan Openswan 2.4.2 Openswan Openswan 2.4 Openswan Openswan 2.3.1 Openswan Openswan 2.3 Openswan Openswan 2.6.36 Openswan Openswan 2.6.35 Openswan Openswan 2.6.33 Openswan Openswan 2.6.29 Openswan Openswan 2.6.28 Openswan Openswan 2.6.27 Openswan Openswan 2.6.26 Openswan Openswan 2.6.25 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 |
| Not Vulnerable: |
Openswan Openswan 2.6.37 |
Discussion
Openswan Crpyotgraphic Helper Use After Free Remote Denial Of Service Vulnerability
Openswan is prone to a remote denial-of-service vulnerability due to a use-after-free error.
An attacker may exploit this issue to crash the application, resulting in a denial-of-service condition.
Note: This issue occurs only when Openswan is configured with 'nhelpers=0'.
Openswan 2.3.0 to 2.6.36 are vulnerable.
Openswan is prone to a remote denial-of-service vulnerability due to a use-after-free error.
An attacker may exploit this issue to crash the application, resulting in a denial-of-service condition.
Note: This issue occurs only when Openswan is configured with 'nhelpers=0'.
Openswan 2.3.0 to 2.6.36 are vulnerable.
Exploit / POC
Openswan Crpyotgraphic Helper Use After Free Remote Denial Of Service Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Openswan Crpyotgraphic Helper Use After Free Remote Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva openswan-2.6.16-1.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva openswan-doc-2.6.16-1.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva openswan-2.6.16-1.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva openswan-doc-2.6.16-1.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
References
Openswan Crpyotgraphic Helper Use After Free Remote Denial Of Service Vulnerability
References:
References:
- Openswan Homepage (Openswan)
- ASA-2011-356 openswan security update (RHSA-2011-1422) (Avaya)
- CVE-2013-6466 Openswan IKEv2 payloads denial of service (Openswan)