CVE-2010-3308: Code Injection
Published Oct 5, 2010
·Updated
Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of service via a long ciscobanner (aka serverbanner) field.
Affected Software
3 affected components
Xelerance Openswan=2.6.26
Xelerance Openswan=2.6.27
Xelerance Openswan=2.6.28
Remediation
Event History
Oct 5, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3308?
CVE-2010-3308 is rated as high severity due to the potential for remote code execution or denial of service.
2
How do I fix CVE-2010-3308?
To fix CVE-2010-3308, upgrade Openswan to a version later than 2.6.28 where the vulnerability is patched.
3
Who is impacted by CVE-2010-3308?
CVE-2010-3308 affects users of Openswan versions 2.6.26 through 2.6.28.
4
What type of vulnerability is CVE-2010-3308?
CVE-2010-3308 is a buffer overflow vulnerability related to the handling of long input in the cisco_banner field.
5
Can CVE-2010-3308 lead to data compromise?
Yes, CVE-2010-3308 can allow attackers to execute arbitrary code, potentially leading to data compromise.