FreeS/WAN X.509 Patch Certificate Verification Vulnerability

Bugtraq ID: 10611
Class: Access Validation Error
CVE: CVE-2004-0590
Remote: Yes
Local: No
Published: Jun 25 2004 12:00AM
Updated: Jul 12 2009 05:16AM
Credit: Discovery of this vulnerability is credited to Thomas Walpuski <thomas@unproved.org>.
Vulnerable: Super FreeS/WAN Super FreeS/WAN 1.99.7 .3
strongSwan strongSwan 2.1.3
Openswan Openswan 2.1.2
Openswan Openswan 2.1.1
Openswan Openswan 1.0.5
Openswan Openswan 1.0.4
Gentoo Linux 1.4 _rc3
Gentoo Linux 1.4 _rc2
Gentoo Linux 1.4 _rc1
Gentoo Linux 1.4
FreeS/WAN FreeS/WAN 2.4 -r1
FreeS/WAN FreeS/WAN 1.9.6
- Debian Linux 3.0 sparc
- Debian Linux 3.0 s/390
- Debian Linux 3.0 ppc
- Debian Linux 3.0 mipsel
- Debian Linux 3.0 mips
- Debian Linux 3.0 m68k
- Debian Linux 3.0 ia-64
- Debian Linux 3.0 ia-32
- Debian Linux 3.0 hppa
- Debian Linux 3.0 arm
- Debian Linux 3.0 alpha
FreeS/WAN FreeS/WAN 1.9.5
FreeS/WAN FreeS/WAN 1.9.4
FreeS/WAN FreeS/WAN 1.9.3
FreeS/WAN FreeS/WAN 1.9.2
FreeS/WAN FreeS/WAN 1.9.1
FreeS/WAN FreeS/WAN 1.9
Andreas Steffen x509 patch 1.5.5
Andreas Steffen x509 patch 1.5.4
Andreas Steffen x509 patch 0.9.39
Not Vulnerable: Andreas Steffen x509 patch 1.6.1
+ FreeS/WAN FreeS/WAN 2.4 -r1
+ FreeS/WAN FreeS/WAN 2.0 5
+ FreeS/WAN FreeS/WAN 2.0 4
Andreas Steffen x509 patch 0.9.41
+ FreeS/WAN FreeS/WAN 1.99


 

Privacy Statement
Copyright 2010, SecurityFocus