CVE Vulnerabilities

CVE-2004-0590

Published: Dec 06, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.

Affected Software

Name Vendor Start Version End Version
Frees_wan Frees_wan 1 (including) 1 (including)
Frees_wan Frees_wan 2 (including) 2 (including)
Super_frees_wan Frees_wan 1 (including) 1 (including)
Openswan Openswan 1 (including) 1 (including)
Openswan Openswan 2 (including) 2 (including)
Strongswan Strongswan * 2.1.2 (including)

References