CVE-2013-2054
published 2013-07-09CVE-2013-2054: Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote…
PriorityP427medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
2.02%
78.7th percentile
Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
Affected
142 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libreswan | — | — |
| debian | strongswan | < strongswan 4.3.4-1 (bookworm) | strongswan 4.3.4-1 (bookworm) |
| libreswan | libreswan | — | — |
| libreswan | libreswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ghm6-8w78-2p3j: Buffer overflow in the atodn function in libreswan 3
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2013-2052 [MEDIUM] CWE-119 GHSA-ghm6-8w78-2p3j: Buffer overflow in the atodn function in libreswan 3
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
GHSA
GHSA-cr25-xc39-jfqp: Buffer overflow in the atodn function in strongSwan 2
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2013-2054 [MEDIUM] CWE-119 GHSA-cr25-xc39-jfqp: Buffer overflow in the atodn function in strongSwan 2
Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
GHSA
GHSA-xqwx-33f7-54m6: Buffer overflow in the atodn function in Openswan before 2
ghsa_unreviewed·2022-05-14·CVSS 5.1
CVE-2013-2053 [MEDIUM] CWE-119 GHSA-xqwx-33f7-54m6: Buffer overflow in the atodn function in Openswan before 2
Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.
OSV
CVE-2013-2054: Buffer overflow in the atodn function in strongSwan 2
osv·2013-07-09·CVSS 6.8
CVE-2013-2054 [MEDIUM] CVE-2013-2054: Buffer overflow in the atodn function in strongSwan 2
Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
Red Hat
Openswan: remote buffer overflow in atodn()
vendor_redhat·2013-05-13·CVSS 5.1
CVE-2013-2053 [MEDIUM] CWE-119 Openswan: remote buffer overflow in atodn()
Openswan: remote buffer overflow in atodn()
Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.
Debian
CVE-2013-2052: libreswan - Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunist...
vendor_debian·2013·CVSS 5.1
CVE-2013-2052 [MEDIUM] CVE-2013-2052: libreswan - Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunist...
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2013-2054: strongswan - Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Op...
vendor_debian·2013·CVSS 6.8
CVE-2013-2054 [MEDIUM] CVE-2013-2054: strongswan - Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Op...
Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054.
Scope: local
bookworm: resolved (fixed in 4.3.4-1)
bullseye: resolved (fixed in 4.3.4-1)
forky: resolved (fixed in 4.3.4-1)
sid: resolved (fixed in 4.3.4-1)
trixie: resolved (fixed in 4.3.4-1)
No detection rules found.
No public exploits indexed.
http://download.strongswan.org/security/CVE-2013-2054/CVE-2013-2054.txthttp://www.securityfocus.com/bid/59837https://lists.libreswan.org/pipermail/swan-announce/2013/000003.htmlhttp://download.strongswan.org/security/CVE-2013-2054/CVE-2013-2054.txthttp://www.securityfocus.com/bid/59837https://lists.libreswan.org/pipermail/swan-announce/2013/000003.html
2013-07-09
Published