- EPSS 1.79%
- Veröffentlicht 04.08.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service...
- EPSS 6.3%
- Veröffentlicht 25.06.2009 02:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attacker...
- EPSS 1.74%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic ...
- EPSS 1.74%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_...
- EPSS 10.86%
- Veröffentlicht 01.04.2009 10:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_...
- EPSS 1.24%
- Veröffentlicht 14.10.2008 20:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NULL values in a Key Exchange payload, which triggers a NULL pointer dereference for the return value o...
- EPSS 0.58%
- Veröffentlicht 06.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a sel...