[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247213

 
 

909

 
 

194329

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-2185Date: (C)2009-06-24   (M)2023-12-22


The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1022428
BID-35452
SECUNIA-35522
SECUNIA-35698
SECUNIA-35740
SECUNIA-35804
SECUNIA-36922
SECUNIA-36950
SECUNIA-37504
ADV-2009-1639
ADV-2009-1706
ADV-2009-1829
ADV-2009-3354
DSA-1898
DSA-1899
FEDORA-2009-7423
FEDORA-2009-7478
RHSA-2009:1138
http://download.strongswan.org/CHANGES2.txt
http://download.strongswan.org/CHANGES4.txt
http://download.strongswan.org/CHANGES42.txt
http://up2date.astaro.com/2009/07/up2date_7404_released.html
http://www.ingate.com/Relnote.php?ver=481
oval:org.mitre.oval:def:11079

CPE    29
cpe:/a:strongswan:strongswan:4.3.1
cpe:/a:strongswan:strongswan:4.3.0
cpe:/a:strongswan:strongswan:2.8.8
cpe:/a:strongswan:strongswan:2.8.9
...
CWE    1
CWE-20
OVAL    9
oval:org.mitre.oval:def:8047
oval:org.secpod.oval:def:600430
oval:org.secpod.oval:def:102251
oval:org.secpod.oval:def:202051
...

© SecPod Technologies