CVE-2013-2053

Public on 2013-05-24
Modified on 2014-09-15
Description
Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.
Severity
Important severity
Important
CVSS v3 Base Score
7.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 openswan 2013-05-24 ALAS-2013-192 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 7.6 AV:N/AC:H/Au:N/C:C/I:C/A:C
NVD CVSSv2 6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P