4
CVSSv2

CVE-2011-4073

Published: 17/11/2011 Updated: 29/07/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 up to and including 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.

Vulnerable Product Search on Vulmon Subscribe to Product

xelerance openswan 2.4.2

xelerance openswan 2.4.10

xelerance openswan 2.4.4

xelerance openswan 2.5.0

xelerance openswan 2.5.12

xelerance openswan 2.5.13

xelerance openswan 2.5.14

xelerance openswan 2.5.15

xelerance openswan 2.6.09

xelerance openswan 2.6.10

xelerance openswan 2.6.11

xelerance openswan 2.6.12

xelerance openswan 2.6.27

xelerance openswan 2.6.30

xelerance openswan 2.6.26

xelerance openswan 2.6.25

xelerance openswan 2.4.5

xelerance openswan 2.4.3

xelerance openswan 2.4.6

xelerance openswan 2.4.7

xelerance openswan 2.5.04

xelerance openswan 2.5.05

xelerance openswan 2.5.06

xelerance openswan 2.6.04

xelerance openswan 2.6.05

xelerance openswan 2.6.06

xelerance openswan 2.5.16

xelerance openswan 2.6.28

xelerance openswan 2.6.29

xelerance openswan 2.6.20

xelerance openswan 2.6.19

xelerance openswan 2.6.22

xelerance openswan 2.6.31

xelerance openswan 2.6.21

xelerance openswan 2.6.32

xelerance openswan 2.3.1

xelerance openswan 2.4.11

xelerance openswan 2.4.1

xelerance openswan 2.5.01

xelerance openswan 2.5.03

xelerance openswan 2.5.08

xelerance openswan 2.5.10

xelerance openswan 2.6.01

xelerance openswan 2.6.03

xelerance openswan 2.5.17

xelerance openswan 2.6.07

xelerance openswan 2.6.14

xelerance openswan 2.6.15

xelerance openswan 2.6.17

xelerance openswan 2.6.36

xelerance openswan 2.6.24

xelerance openswan 2.6.23

xelerance openswan 2.3.0

xelerance openswan 2.4.0

xelerance openswan 2.4.8

xelerance openswan 2.4.9

xelerance openswan 2.5.02

xelerance openswan 2.5.07

xelerance openswan 2.5.09

xelerance openswan 2.5.11

xelerance openswan 2.4.12

xelerance openswan 2.6.02

xelerance openswan 2.5.18

xelerance openswan 2.6.08

xelerance openswan 2.6.13

xelerance openswan 2.4.13

xelerance openswan 2.6.16

xelerance openswan 2.6.18

xelerance openswan 2.6.35

xelerance openswan 2.6.33

xelerance openswan 2.6.34

Vendor Advisories

The information security group at ETH Zurich discovered a denial of service vulnerability in the crypto helper handler of the IKE daemon pluto More information can be found in the upstream advisory For the oldstable distribution (lenny), this problem has been fixed in version 1:2412+dfsg-13+lenny4 For the stable distribution (squeeze), this ...
A use-after-free flaw was found in the way Openswan's pluto IKE daemon used cryptographic helpers A remote, authenticated attacker could send a specially-crafted IKE packet that would crash the pluto daemon This issue only affected SMP (symmetric multiprocessing) systems that have the cryptographic helpers enabled ...