First published: Tue Oct 05 2010(Updated: )
programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns_info or (2) cisco_domain_info data in a packet, a different vulnerability than CVE-2010-3302.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xelerance Openswan | =2.6.25 | |
Xelerance Openswan | =2.6.26 | |
Xelerance Openswan | =2.6.27 | |
Xelerance Openswan | =2.6.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.