← Back

CVE-2013-6075

nvd nist
Published: Nov 2, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.

Affected (22)

1 product
Strongswan
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Strongswan
Version 4.3.3
Version 4.3.4
Version 4.3.5
Version 4.3.6
Version 4.3.7
Version 4.4.0
Version 4.4.1
Version 4.5.0
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.6.0
Version 4.6.1
Version 4.6.2
Version 4.6.3
Version 4.6.4
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.1.0

Timeline

No history available yet.