CVE-2005-0162: Buffer Overflow
Published Jan 26, 2005
·Updated
Stack-based buffer overflow in the getinternaladdresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.
Affected Software
2 affected components
Openswan Openswan<=1.0.9
Xelerance Openswan=2.3.0
Remediation
Patch Available
Event History
Jan 26, 2005
CVE Published
05:00 AM
Jan 29, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0162?
CVE-2005-0162 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2005-0162?
To fix CVE-2005-0162, upgrade Openswan to version 1.0.9 or 2.3.0 or later.
3
Which versions of Openswan are affected by CVE-2005-0162?
CVE-2005-0162 affects Openswan 1.x before 1.0.9 and 2.x before 2.3.0 when compiled with XAUTH and PAM enabled.
4
Can an attacker exploit CVE-2005-0162 without authentication?
No, an attacker must be an authenticated user to exploit CVE-2005-0162.
5
What is the impact of CVE-2005-0162 if exploited?
If exploited, CVE-2005-0162 allows remote authenticated attackers to execute arbitrary code on the affected system.