Libreswan CVE-2013-2052 DNS TXT Record Buffer Overflow Vulnerability
BID:59835
Info
Libreswan CVE-2013-2052 DNS TXT Record Buffer Overflow Vulnerability
| Bugtraq ID: | 59835 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-2052 |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 13 2013 12:00AM |
| Updated: | May 13 2013 12:00AM |
| Credit: | Florian Weimer of the Red Hat Product Security Team |
| Vulnerable: |
Libreswan Libreswan 3.1 Libreswan Libreswan 3.0 |
| Not Vulnerable: |
Libreswan Libreswan 3.3 Libreswan Libreswan 3.2 |
Discussion
Libreswan CVE-2013-2052 DNS TXT Record Buffer Overflow Vulnerability
Libreswan is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application or cause the application to crash, resulting in denial-of-service conditions.
Libreswan 3.0 and 3.1 are vulnerable.
Libreswan is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application or cause the application to crash, resulting in denial-of-service conditions.
Libreswan 3.0 and 3.1 are vulnerable.