Denial of Service Vulnerability in StrongSwan and OpenSwan Products
CVE-2009-2185

Currently unrated

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
25 June 2009

What is CVE-2009-2185?

The vulnerability in the ASN.1 parser of StrongSwan and OpenSwan products allows remote attackers to trigger a denial of service condition. This is achieved by sending specially crafted X.509 certificates that contain manipulated Relative Distinguished Names (RDNs), improper UTCTIME strings, or altered GENERALIZEDTIME strings, leading to crashes in the pluto IKE daemon.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.