CVE-2013-6075: Buffer Overflow
The comparedn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted IDDERASN1DN ID, related to an "insufficient length check" during identity comparison.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6075?
CVE-2013-6075 has been classified as a medium severity vulnerability due to its potential for denial of service and user impersonation.
How do I fix CVE-2013-6075?
To address CVE-2013-6075, update your strongSwan installation to version 5.1.1 or later.
What systems are affected by CVE-2013-6075?
CVE-2013-6075 affects strongSwan versions ranging from 4.3.3 to 5.1.0.
Can CVE-2013-6075 lead to remote execution?
No, CVE-2013-6075 does not allow for remote code execution, but it can cause denial of service.
Who can exploit CVE-2013-6075?
CVE-2013-6075 can be exploited by remote attackers to cause a denial of service or by authenticated users to impersonate others.