Input validation error in Openswan - CVE-2013-2053

 

Input validation error in Openswan - CVE-2013-2053

Published: July 9, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32677
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2053
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote attackers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.


Affected software

Openswan
Amazon Linux AMI
Gentoo Linux
SUSE Linux
openswan (Alpine package)

How to mitigate CVE-2013-2053

Update to version 2.6.39.

Openswan - update to 2.6.39
openswan (Alpine package) - update to 2.6.38-r2

External References

Related Security Bulletins