Lucene search

K
cve[email protected]CVE-2008-4190
HistorySep 24, 2008 - 11:42 a.m.

CVE-2008-4190

2008-09-2411:42:25
CWE-59
web.nvd.nist.gov
31
cve-2008-4190
ipsec
openswan
vulnerability
symlink attack
arbitrary code execution

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

0.4%

The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.

Affected configurations

NVD
Node
openswanopenswanMatch1.0.4
OR
openswanopenswanMatch1.0.5
OR
openswanopenswanMatch1.0.6
OR
openswanopenswanMatch1.0.7
OR
openswanopenswanMatch1.0.8
OR
openswanopenswanMatch1.0.9
OR
openswanopenswanMatch2.1.1
OR
openswanopenswanMatch2.1.2
OR
openswanopenswanMatch2.1.4
OR
openswanopenswanMatch2.1.5
OR
openswanopenswanMatch2.1.6
OR
openswanopenswanMatch2.2
OR
openswanopenswanMatch2.3
OR
xeleranceopenswanMatch2.3.1
OR
xeleranceopenswanMatch2.4.0
OR
xeleranceopenswanMatch2.4.1
OR
xeleranceopenswanMatch2.4.2
OR
xeleranceopenswanMatch2.4.3
OR
xeleranceopenswanMatch2.4.4
OR
xeleranceopenswanMatch2.4.5
OR
xeleranceopenswanMatch2.4.6
OR
xeleranceopenswanMatch2.4.7
OR
xeleranceopenswanMatch2.4.8
OR
xeleranceopenswanMatch2.4.9
OR
xeleranceopenswanMatch2.4.10
OR
xeleranceopenswanMatch2.4.11
OR
xeleranceopenswanMatch2.4.12
OR
xeleranceopenswanMatch2.6.03
OR
xeleranceopenswanMatch2.6.04
OR
xeleranceopenswanMatch2.6.05
OR
xeleranceopenswanMatch2.6.06
OR
xeleranceopenswanMatch2.6.07
OR
xeleranceopenswanMatch2.6.08
OR
xeleranceopenswanMatch2.6.09
OR
xeleranceopenswanMatch2.6.10
OR
xeleranceopenswanMatch2.6.11
OR
xeleranceopenswanMatch2.6.12
OR
xeleranceopenswanMatch2.6.13
OR
xeleranceopenswanMatch2.6.14
OR
xeleranceopenswanMatch2.6.15
OR
xeleranceopenswanMatch2.6.16

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

0.4%