Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-2661
Description:The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.
Test IDs: 1.3.6.1.4.1.25623.1.0.800673   1.3.6.1.4.1.25623.1.0.65722   1.3.6.1.4.1.25623.1.0.65823   1.3.6.1.4.1.25623.1.0.65006   1.3.6.1.4.1.25623.1.0.65117   1.3.6.1.4.1.25623.1.0.65724   1.3.6.1.4.1.25623.1.0.65799  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-2661
Debian Security Information: DSA-1899 (Google Search)
http://www.debian.org/security/2009/dsa-1899
https://lists.strongswan.org/pipermail/announce/2009-July/000056.html
http://www.openwall.com/lists/oss-security/2009/07/27/1
http://secunia.com/advisories/36922
SuSE Security Announcement: SUSE-SR:2009:016 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
SuSE Security Announcement: SUSE-SR:2009:018 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html
http://www.vupen.com/english/advisories/2009/2247




© 1998-2025 E-Soft Inc. All rights reserved.