Input validation error in Openswan - CVE-2013-2053
Published: July 9, 2013 / Updated: July 28, 2020
Vulnerability identifier: #VU32677
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2053
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.
Affected software
Openswan
Amazon Linux AMI
Gentoo Linux
SUSE Linux
openswan (Alpine package)
Amazon Linux AMI
Gentoo Linux
SUSE Linux
openswan (Alpine package)
How to mitigate CVE-2013-2053
Update to version 2.6.39.
Openswan - update to 2.6.39
openswan (Alpine package) - update to 2.6.38-r2
openswan (Alpine package) - update to 2.6.38-r2
External References
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00008.html
- http://rhn.redhat.com/errata/RHSA-2013-0827.html
- http://www.debian.org/security/2014/dsa-2893
- http://www.securityfocus.com/bid/59838
- https://bugzilla.redhat.com/show_bug.cgi?id=960229
- https://lists.libreswan.org/pipermail/swan-announce/2013/000003.html
- https://www.openswan.org/news/13