strongSwan CVE-2013-2054 DNS TXT Record Buffer Overflow Vulnerability
BID:59837
Info
strongSwan CVE-2013-2054 DNS TXT Record Buffer Overflow Vulnerability
| Bugtraq ID: | 59837 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-2054 |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 13 2013 12:00AM |
| Updated: | Sep 03 2013 12:09AM |
| Credit: | Florian Weimer of the Red Hat Product Security Team |
| Vulnerable: |
strongSwan strongSwan 4.3.3 strongSwan strongSwan 4.3.2 strongSwan strongSwan 4.3.1 strongSwan strongSwan 4.3 strongSwan strongSwan 4.2.17 strongSwan strongSwan 4.2.16 strongSwan strongSwan 4.2.15 strongSwan strongSwan 4.2.14 strongSwan strongSwan 4.2.13 strongSwan strongSwan 4.2.7 strongSwan strongSwan 4.2.6 strongSwan strongSwan 4.1 strongSwan strongSwan 2.8.11 strongSwan strongSwan 2.8.10 strongSwan strongSwan 2.8.9 strongSwan strongSwan 2.8.8 strongSwan strongSwan 2.1.3 strongSwan strongSwan 4.3.4 Gentoo Linux |
| Not Vulnerable: | |
Discussion
strongSwan CVE-2013-2054 DNS TXT Record Buffer Overflow Vulnerability
strongSwan is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application or cause the application to crash, resulting in denial-of-service conditions.
strongSwan 1.0 through 4.3.4 are vulnerable.
strongSwan is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application or cause the application to crash, resulting in denial-of-service conditions.
strongSwan 1.0 through 4.3.4 are vulnerable.
Exploit / POC
strongSwan CVE-2013-2054 DNS TXT Record Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
strongSwan CVE-2013-2054 DNS TXT Record Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
strongSwan CVE-2013-2054 DNS TXT Record Buffer Overflow Vulnerability
References:
References:
- strongSwan Homepage (strongSwan)