PT-2011-1134 · Openswan+1 · Openswan+1
Published
2011-11-02
·
Updated
2019-07-29
·
CVE-2011-4073
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Openswan versions 2.3.0 through 2.6.36
Description
The issue is related to a use-after-free vulnerability in the cryptographic helper handler functionality. This vulnerability allows remote authenticated users to cause a denial of service, specifically a crash of the pluto IKE daemon, via vectors related to the
quick outI1 continue and quick outI1 functions. The vulnerability can be exploited remotely by an authenticated attacker, leading to a disruption of protected information.Recommendations
For Openswan versions 2.3.0 through 2.6.36, consider updating to a version newer than 2.6.36 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openswan
Red Hat