CVE-2009-2661: Medium severity strongswan vulnerability
The asn1length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2661?
CVE-2009-2661 is classified as a denial of service vulnerability affecting specific versions of strongSwan.
How do I fix CVE-2009-2661?
To address CVE-2009-2661, you should upgrade to strongSwan version 2.8.11, 4.2.17, or 4.3.3 or later.
What software versions are affected by CVE-2009-2661?
CVE-2009-2661 affects strongSwan versions 2.8.0 to 2.8.10 and 4.2.0 to 4.2.16.
What impact does CVE-2009-2661 have on systems?
CVE-2009-2661 allows attackers to crash the pluto IKE daemon, resulting in a denial of service.
Is CVE-2009-2661 a remotely exploitable vulnerability?
Yes, CVE-2009-2661 can be exploited remotely by sending crafted ASN.1 data to the affected strongSwan versions.