LWN.net Logo

openswan: code execution

Package(s):openswan CVE #(s):CVE-2010-3752 CVE-2010-3753
Created:November 17, 2010 Updated:November 17, 2010
Description: From the Red Hat advisory: two input sanitization flaws were found in the Openswan client-side handling of Cisco gateway banners. A malicious or compromised VPN gateway could use these flaws to execute arbitrary code on the connecting Openswan client.
Alerts:
Red Hat RHSA-2010:0892-01 2010-11-16
Mageia MGASA-2012-0300 2012-10-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds