Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openswan | Xelerance | 2.3.0 (including) | 2.3.0 (including) |
Openswan | Xelerance | 2.3.1 (including) | 2.3.1 (including) |
Openswan | Xelerance | 2.4.0 (including) | 2.4.0 (including) |
Openswan | Xelerance | 2.4.1 (including) | 2.4.1 (including) |
Openswan | Xelerance | 2.4.2 (including) | 2.4.2 (including) |
Openswan | Xelerance | 2.4.3 (including) | 2.4.3 (including) |
Openswan | Xelerance | 2.4.4 (including) | 2.4.4 (including) |
Openswan | Xelerance | 2.4.5 (including) | 2.4.5 (including) |
Openswan | Xelerance | 2.4.6 (including) | 2.4.6 (including) |
Openswan | Xelerance | 2.4.7 (including) | 2.4.7 (including) |
Openswan | Xelerance | 2.4.8 (including) | 2.4.8 (including) |
Openswan | Xelerance | 2.4.9 (including) | 2.4.9 (including) |
Openswan | Xelerance | 2.4.10 (including) | 2.4.10 (including) |
Openswan | Xelerance | 2.4.11 (including) | 2.4.11 (including) |
Openswan | Xelerance | 2.4.12 (including) | 2.4.12 (including) |
Openswan | Xelerance | 2.4.13 (including) | 2.4.13 (including) |
Openswan | Xelerance | 2.5.0 (including) | 2.5.0 (including) |
Openswan | Xelerance | 2.5.0-sbs4 (including) | 2.5.0-sbs4 (including) |
Openswan | Xelerance | 2.5.0-sbs5 (including) | 2.5.0-sbs5 (including) |
Openswan | Xelerance | 2.5.01 (including) | 2.5.01 (including) |
Openswan | Xelerance | 2.5.02 (including) | 2.5.02 (including) |
Openswan | Xelerance | 2.5.03 (including) | 2.5.03 (including) |
Openswan | Xelerance | 2.5.04 (including) | 2.5.04 (including) |
Openswan | Xelerance | 2.5.05 (including) | 2.5.05 (including) |
Openswan | Xelerance | 2.5.06 (including) | 2.5.06 (including) |
Openswan | Xelerance | 2.5.07 (including) | 2.5.07 (including) |
Openswan | Xelerance | 2.5.08 (including) | 2.5.08 (including) |
Openswan | Xelerance | 2.5.09 (including) | 2.5.09 (including) |
Openswan | Xelerance | 2.5.10 (including) | 2.5.10 (including) |
Openswan | Xelerance | 2.5.11 (including) | 2.5.11 (including) |
Openswan | Xelerance | 2.5.12 (including) | 2.5.12 (including) |
Openswan | Xelerance | 2.5.13 (including) | 2.5.13 (including) |
Openswan | Xelerance | 2.5.14 (including) | 2.5.14 (including) |
Openswan | Xelerance | 2.5.15 (including) | 2.5.15 (including) |
Openswan | Xelerance | 2.5.16 (including) | 2.5.16 (including) |
Openswan | Xelerance | 2.5.17 (including) | 2.5.17 (including) |
Openswan | Xelerance | 2.5.18 (including) | 2.5.18 (including) |
Openswan | Xelerance | 2.6.01 (including) | 2.6.01 (including) |
Openswan | Xelerance | 2.6.02 (including) | 2.6.02 (including) |
Openswan | Xelerance | 2.6.03 (including) | 2.6.03 (including) |
Openswan | Xelerance | 2.6.04 (including) | 2.6.04 (including) |
Openswan | Xelerance | 2.6.05 (including) | 2.6.05 (including) |
Openswan | Xelerance | 2.6.06 (including) | 2.6.06 (including) |
Openswan | Xelerance | 2.6.07 (including) | 2.6.07 (including) |
Openswan | Xelerance | 2.6.08 (including) | 2.6.08 (including) |
Openswan | Xelerance | 2.6.09 (including) | 2.6.09 (including) |
Openswan | Xelerance | 2.6.10 (including) | 2.6.10 (including) |
Openswan | Xelerance | 2.6.11 (including) | 2.6.11 (including) |
Openswan | Xelerance | 2.6.12 (including) | 2.6.12 (including) |
Openswan | Xelerance | 2.6.13 (including) | 2.6.13 (including) |
Openswan | Xelerance | 2.6.14 (including) | 2.6.14 (including) |
Openswan | Xelerance | 2.6.15 (including) | 2.6.15 (including) |
Openswan | Xelerance | 2.6.16 (including) | 2.6.16 (including) |
Openswan | Xelerance | 2.6.17 (including) | 2.6.17 (including) |
Openswan | Xelerance | 2.6.18 (including) | 2.6.18 (including) |
Openswan | Xelerance | 2.6.19 (including) | 2.6.19 (including) |
Openswan | Xelerance | 2.6.20 (including) | 2.6.20 (including) |
Openswan | Xelerance | 2.6.21 (including) | 2.6.21 (including) |
Openswan | Xelerance | 2.6.22 (including) | 2.6.22 (including) |
Openswan | Xelerance | 2.6.23 (including) | 2.6.23 (including) |
Openswan | Xelerance | 2.6.24 (including) | 2.6.24 (including) |
Openswan | Xelerance | 2.6.25 (including) | 2.6.25 (including) |
Openswan | Xelerance | 2.6.26 (including) | 2.6.26 (including) |
Openswan | Xelerance | 2.6.27 (including) | 2.6.27 (including) |
Openswan | Xelerance | 2.6.28 (including) | 2.6.28 (including) |
Openswan | Xelerance | 2.6.29 (including) | 2.6.29 (including) |
Openswan | Xelerance | 2.6.30 (including) | 2.6.30 (including) |
Openswan | Xelerance | 2.6.31 (including) | 2.6.31 (including) |
Openswan | Xelerance | 2.6.32 (including) | 2.6.32 (including) |
Openswan | Xelerance | 2.6.33 (including) | 2.6.33 (including) |
Openswan | Xelerance | 2.6.34 (including) | 2.6.34 (including) |
Openswan | Xelerance | 2.6.35 (including) | 2.6.35 (including) |
Openswan | Xelerance | 2.6.36 (including) | 2.6.36 (including) |
Red Hat Enterprise Linux 5 | RedHat | openswan-0:2.6.21-5.el5_7.6 | * |
Red Hat Enterprise Linux 6 | RedHat | openswan-0:2.6.32-4.el6_1.4 | * |
Openswan | Ubuntu | hardy | * |
Openswan | Ubuntu | lucid | * |
Openswan | Ubuntu | maverick | * |
Openswan | Ubuntu | natty | * |
Openswan | Ubuntu | oneiric | * |
Openswan | Ubuntu | upstream | * |