Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openswan. | Aug 30, 2017 | Jul 9, 2013 |
| Centos_linux | — | Upgrade openswanUpgrade openswan-doc | Dec 1, 2016 | Jul 9, 2013 |
| Gentoo Linux | — | Upgrade net-misc/openswan. | Oct 30, 2017 | Jul 9, 2013 |
| Oracle_linux | — | Upgrade openswan-docUpgrade openswan | Oct 16, 2024 | Jul 9, 2013 |
| Suse | — | Upgrade openswan-docUpgrade openswan | Feb 17, 2015 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub