CVE-2010-3752: OS Command Injection
programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) ciscodnsinfo or (2) ciscodomaininfo data in a packet, a different vulnerability than CVE-2010-3302.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3752?
CVE-2010-3752 is considered a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2010-3752?
To fix CVE-2010-3752, upgrade OpenSWAN to a version higher than 2.6.28 where the vulnerability has been addressed.
What systems are affected by CVE-2010-3752?
CVE-2010-3752 affects OpenSWAN versions 2.6.25 through 2.6.28.
What type of attack does CVE-2010-3752 enable?
CVE-2010-3752 enables attackers to execute arbitrary commands on the vulnerable system via crafted packets.
Is authentication required to exploit CVE-2010-3752?
Yes, CVE-2010-3752 requires the attacker to have a remote authenticated gateway to exploit the vulnerability.