6.5
CVSSv2

CVE-2010-3752

Published: 05/10/2010 Updated: 29/07/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

programs/pluto/xauth.c in the client in Openswan 2.6.25 up to and including 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns_info or (2) cisco_domain_info data in a packet, a different vulnerability than CVE-2010-3302.

Vulnerable Product Search on Vulmon Subscribe to Product

xelerance openswan 2.6.25

xelerance openswan 2.6.26

xelerance openswan 2.6.27

xelerance openswan 2.6.28

Vendor Advisories

Debian Bug report logs - #599515 bind9: CVE-2010-3762 Package: bind9; Maintainer for bind9 is Debian DNS Team <team+dns@trackerdebianorg>; Source for bind9 is src:bind9 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, 8 Oct 2010 10:33:01 UTC Severity: grave Tags: securi ...