PT-2011-1179 · Openswan · Openswan

Helpermn

·

Published

2011-05-20

·

Updated

2017-08-29

·

CVE-2011-2147

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Openswan versions 2.2.x through 2.6.37
Description The issue is related to improper permission restrictions in Openswan, specifically with files /var/run/starter.pid and /var/lock/subsys/ipsec. This could allow local users to kill arbitrary processes or bypass disk quotas by writing to these files. The vulnerability can be exploited remotely by an authenticated attacker, potentially leading to disruption of protected information.
Recommendations For Openswan versions 2.2.x through 2.6.37, consider restricting access to the /var/run/starter.pid and /var/lock/subsys/ipsec files to prevent unauthorized modifications. As a temporary workaround, restrict write permissions to these files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09437
CVE-2011-2147

Affected Products

Openswan