VDB
CVE-2009-2185
CVE-2009-2185
PUBLISHED
CVSS 5 MEDIUM
The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.
EPSS 8.23% · 92.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
8.23%
92.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| xelerance | openswan | 2.6.18, 2.4.0, 2.4.1 |
| strongswan | strongswan | 4.3.0, 4.3.1, 2.8.6 |
| n/a | n/a | n/a |
Timeline
- Jun 24, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- ADV-2009-1639 vdb
- 35740 third-party-advisory
- http://www.ingate.com/Relnote.php?ver=481 url
- 1022428 vdb
- RHSA-2009:1138 vendor-advisory
- ADV-2009-1706 vdb
- oval:org.mitre.oval:def:11079 vdb
- 36950 third-party-advisory
- 35522 third-party-advisory
- 36922 third-party-advisory
- 37504 third-party-advisory
- DSA-1899 vendor-advisory
- 35452 vdb
- http://download.strongswan.org/CHANGES42.txt url
- http://download.strongswan.org/CHANGES2.txt url
- http://up2date.astaro.com/2009/07/up2date_7404_released.html url
- DSA-1898 vendor-advisory
- ADV-2009-1829 vdb
- FEDORA-2009-7478 vendor-advisory
- 35698 third-party-advisory
…and 5 more