cbcvebase.
CVE-2013-6075
published 2013-11-02

CVE-2013-6075: The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds…

PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.45%
82.5th percentile
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianstrongswan< strongswan 5.1.0-3 (bookworm)strongswan 5.1.0-3 (bookworm)
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan>= 0 < 5.1.0-35.1.0-3
strongswanstrongswan>= 0 < 5.1.0-35.1.0-3

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.