LWN.net Logo

openswan: input validation flaws

Package(s):openswan CVE #(s):CVE-2009-2185
Created:July 2, 2009 Updated:October 13, 2009
Description: openswan has multiple input validation flaws. From the Red Hat alert: Multiple insufficient input validation flaws were found in the way Openswan's pluto IKE daemon processed some fields of X.509 certificates. A remote attacker could provide a specially-crafted X.509 certificate that would crash the pluto daemon. (CVE-2009-2185)
Alerts:
Gentoo 200909-05 2009-09-09
SuSE SUSE-SR:2009:013 2009-08-11
Fedora FEDORA-2009-7478 2009-07-11
Fedora FEDORA-2009-7423 2009-07-11
CentOS CESA-2009:1138 2009-07-02
Red Hat RHSA-2009:1138-01 2009-07-02
Mandriva MDVSA-2009:273 2009-10-12
Debian DSA-1899-1 2009-10-02
Debian DSA-1898-1 2009-10-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds