Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 385815 (CVE-2011-3380) - net-misc/openswan multiple vulnerabilites (CVE-2010-{3302,3308,3752,3753},CVE-2011-3380)
Summary: net-misc/openswan multiple vulnerabilites (CVE-2010-{3302,3308,3752,3753},CVE...
Status: RESOLVED FIXED
Alias: CVE-2011-3380
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-05 22:38 UTC by daavelino
Modified: 2011-11-18 06:18 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description daavelino 2011-10-05 22:38:56 UTC
openswan-2.6.29 is affected. It is masked but please, check if our are too.
openswan-2.6.36 seem to be ok. Could someone test and give us feedback?
Comment 1 Agostino Sarubbo gentoo-dev 2011-10-06 15:11:50 UTC
(In reply to comment #0)
> openswan-2.6.29 is affected. It is masked but please, check if our are too.
> openswan-2.6.36 seem to be ok. Could someone test and give us feedback?

Not masked, simply ~testing.

Please bump 2.6.36
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 00:53:57 UTC
CVE-2010-3753 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3753):
  programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28
  allows remote authenticated gateways to execute arbitrary commands via shell
  metacharacters in the cisco_banner (aka server_banner) field, a different
  vulnerability than CVE-2010-3308.

CVE-2010-3752 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3752):
  programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28
  allows remote authenticated gateways to execute arbitrary commands via shell
  metacharacters in (1) cisco_dns_info or (2) cisco_domain_info data in a
  packet, a different vulnerability than CVE-2010-3302.

CVE-2010-3308 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3308):
  Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26
  through 2.6.28 might allow remote authenticated gateways to execute
  arbitrary code or cause a denial of service via a long cisco_banner (aka
  server_banner) field.

CVE-2010-3302 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3302):
  Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.25
  through 2.6.28 might allow remote authenticated gateways to execute
  arbitrary code or cause a denial of service via long (1) cisco_dns_info or
  (2) cisco_domain_info data in a packet.
Comment 3 Agostino Sarubbo gentoo-dev 2011-11-08 20:40:23 UTC
2.6.37 in tree, close as noglsa.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2011-11-18 06:18:42 UTC
CVE-2011-3380 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3380):
  Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of
  service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP
  message with an invalid KEY_LENGTH attribute, which is not properly handled
  by the error handling function.