CVE-2010-3753: OS Command Injection
programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the ciscobanner (aka serverbanner) field, a different vulnerability than CVE-2010-3308.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3753?
CVE-2010-3753 has a high severity as it allows remote authenticated gateways to execute arbitrary commands.
How do I fix CVE-2010-3753?
Fix CVE-2010-3753 by upgrading to Openswan version 2.6.29 or later where the vulnerability has been addressed.
Which versions of Openswan are affected by CVE-2010-3753?
Openswan versions 2.6.26, 2.6.27, and 2.6.28 are affected by CVE-2010-3753.
What vulnerability does CVE-2010-3753 address?
CVE-2010-3753 addresses a vulnerability that allows arbitrary command execution via shell metacharacters in the server_banner field.
Is CVE-2010-3753 a known issue in Openswan?
Yes, CVE-2010-3753 is recognized as a security issue in specific versions of Openswan, identified in security advisories.