PT-2013-5941 · Strongswan+2 · Strongswan+2

Published

2013-11-02

·

Updated

2024-06-15

·

CVE-2013-6075

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions strongSwan versions 4.3.3 through 5.1.1
Description The issue allows remote attackers to cause a denial of service, including out-of-bounds read, NULL pointer dereference, and daemon crash, or remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID DER ASN1 DN ID. This is related to an insufficient length check during identity comparison.
Recommendations For strongSwan versions 4.3.3 through 5.1.1, update to a version that addresses the insufficient length check issue in the compare dn function.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1255
CVE-2013-6075
DSA-2789-1
OPENSUSE-SU-2024:10579-1

Affected Products

Alt Linux
Suse
Strongswan