The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://download.strongswan.org/CHANGES2.txt - Vendor Advisory | |
References | () http://download.strongswan.org/CHANGES4.txt - Vendor Advisory | |
References | () http://download.strongswan.org/CHANGES42.txt - Vendor Advisory | |
References | () http://secunia.com/advisories/35522 - Vendor Advisory | |
References | () http://secunia.com/advisories/35698 - | |
References | () http://secunia.com/advisories/35740 - | |
References | () http://secunia.com/advisories/35804 - | |
References | () http://secunia.com/advisories/36922 - | |
References | () http://secunia.com/advisories/36950 - | |
References | () http://secunia.com/advisories/37504 - | |
References | () http://up2date.astaro.com/2009/07/up2date_7404_released.html - | |
References | () http://www.debian.org/security/2009/dsa-1898 - | |
References | () http://www.debian.org/security/2009/dsa-1899 - | |
References | () http://www.ingate.com/Relnote.php?ver=481 - | |
References | () http://www.redhat.com/support/errata/RHSA-2009-1138.html - | |
References | () http://www.securityfocus.com/bid/35452 - Patch | |
References | () http://www.securitytracker.com/id?1022428 - | |
References | () http://www.vupen.com/english/advisories/2009/1639 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2009/1706 - | |
References | () http://www.vupen.com/english/advisories/2009/1829 - | |
References | () http://www.vupen.com/english/advisories/2009/3354 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11079 - | |
References | () https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00264.html - | |
References | () https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00337.html - |
Information
Published : 2009-06-25 02:00
Updated : 2024-11-21 01:04
NVD link : CVE-2009-2185
Mitre link : CVE-2009-2185
CVE.ORG link : CVE-2009-2185
JSON object : View
Products Affected
xelerance
- openswan
strongswan
- strongswan
CWE
CWE-20
Improper Input Validation