CVE-2013-6075
published 2013-11-02CVE-2013-6075: The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.45%
82.5th percentile
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | strongswan | < strongswan 5.1.0-3 (bookworm) | strongswan 5.1.0-3 (bookworm) |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | >= 0 < 5.1.0-3 | 5.1.0-3 |
| strongswan | strongswan | >= 0 < 5.1.0-3 | 5.1.0-3 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
strongswan: denial of service and potential authorization bypass
vendor_redhat·2013-11-01·CVSS 5.0
CVE-2013-6075 [MEDIUM] strongswan: denial of service and potential authorization bypass
strongswan: denial of service and potential authorization bypass
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.
Statement: Not vulnerable. This issue did not affect the versions of openswan as shipped with Red Hat Enterprise Linux 5 and 6.
Package: openswan (Red Hat Enterprise Linux 5) - Not affected
Package: openswan (Red Hat Enterprise Linux 6) - Not affected
Package: openswan (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6075: strongswan - The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5....
vendor_debian·2013·CVSS 5.0
CVE-2013-6075 [MEDIUM] CVE-2013-6075: strongswan - The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5....
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.
Scope: local
bookworm: resolved (fixed in 5.1.0-3)
bullseye: resolved (fixed in 5.1.0-3)
forky: resolved (fixed in 5.1.0-3)
sid: resolved (fixed in 5.1.0-3)
trixie: resolved (fixed in 5.1.0-3)
GHSA
GHSA-pv47-47g7-w845: The compare_dn function in utils/identification
ghsa_unreviewed·2022-05-17
CVE-2013-6075 [MEDIUM] CWE-119 GHSA-pv47-47g7-w845: The compare_dn function in utils/identification
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.
OSV
CVE-2013-6075: The compare_dn function in utils/identification
osv·2013-11-02·CVSS 5.0
CVE-2013-6075 [MEDIUM] CVE-2013-6075: The compare_dn function in utils/identification
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6075 strongswan: denial of service and potential authorization bypass [fedora-all]
bugzilla·2013-11-02·CVSS 5.0
CVE-2013-6075 [MEDIUM] CVE-2013-6075 strongswan: denial of service and potential authorization bypass [fedora-all]
CVE-2013-6075 strongswan: denial of service and potential authorization bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-6075 strongswan: denial of service and potential authorization bypass [epel-6]
bugzilla·2013-11-02·CVSS 5.0
CVE-2013-6075 [MEDIUM] CVE-2013-6075 strongswan: denial of service and potential authorization bypass [epel-6]
CVE-2013-6075 strongswan: denial of service and potential authorization bypass [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 track
Bugzilla
CVE-2013-6075 strongswan: denial of service and potential authorization bypass
bugzilla·2013-11-01·CVSS 5.0
CVE-2013-6075 [MEDIUM] CVE-2013-6075 strongswan: denial of service and potential authorization bypass
CVE-2013-6075 strongswan: denial of service and potential authorization bypass
A denial of service vulnerability was discovered in strongSwan's IKDE daemon charon. This flaw can be triggered by a crafted ID_DER_ASN1_DN ID payload and is caused by an insufficient length check when comparing such identities. This could cause a memory read outside specified boundaries or a NULL dereference which would result in an IKE daemon crash. As no write operation is performed, code injection is unlikely.
As well, with a crafted ID payload, an attacker could impersonate a different user and get access to VPN connection profiles the victim would have access to. However, this would require that the attacker successfully authenticate with appropriate credentials, and as such upstream indicates that it se
http://download.strongswan.org/security/CVE-2013-6075/strongswan-4.3.3-5.1.0_id_dn_match.patchhttp://www.debian.org/security/2012/dsa-2789http://www.strongswan.org/blog/2013/11/01/strongswan-denial-of-service-vulnerability-%28cve-2013-6075%29.htmlhttp://download.strongswan.org/security/CVE-2013-6075/strongswan-4.3.3-5.1.0_id_dn_match.patchhttp://www.debian.org/security/2012/dsa-2789http://www.strongswan.org/blog/2013/11/01/strongswan-denial-of-service-vulnerability-%28cve-2013-6075%29.html
2013-11-02
Published