7.5
CVSSv2

CVE-2010-2628

Published: 20/08/2010 Updated: 24/08/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The IKE daemon in strongSwan 4.3.x prior to 4.3.7 and 4.4.x prior to 4.4.1 does not properly check the return values of snprintf calls, which allows remote malicious users to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows.

Vulnerable Product Search on Vulmon Subscribe to Product

strongswan strongswan 4.3.3

strongswan strongswan 4.3.4

strongswan strongswan 4.3.5

strongswan strongswan 4.3.0

strongswan strongswan 4.3.1

strongswan strongswan 4.3.2

strongswan strongswan 4.3.6

strongswan strongswan 4.4.0