Back to search
CVE-2010-2628
Published: Aug 20, 2010
Modified: Sep 17, 2024
PUBLISHED
Description
The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2010-2086
vdb-entry
x_refsource_VUPEN
[opensuse-updates] 20100810 openSUSE-SU-2010:0496-1 (important): strongswan: fixing snprintf overflows
mailing-list
x_refsource_MLIST
[users] 20100802 ANNOUNCE: strongswan-4.4.1 released
mailing-list
x_refsource_MLIST
ADV-2010-2085
vdb-entry
x_refsource_VUPEN
1024338
vdb-entry
x_refsource_SECTRACK
40956
third-party-advisory
x_refsource_SECUNIA
42444
vdb-entry
x_refsource_BID
https://bugzilla.novell.com/615915
x_refsource_CONFIRM
http://trac.strongswan.org/projects/strongswan/wiki/441
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now