Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10854
HistoryJan 15, 2019 - 8:53 a.m.

Remote Code Execution (RCE)

2019-01-1508:53:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.074

Percentile

94.1%

openswan is vulnerable to remote code execution (RCE) attacks. The vulnerability exists through a buffer overflow issue in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.