VDB
CVE-2010-3308
CVE-2010-3308
PUBLISHED
CVSS 6.5 MEDIUM
Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of service via a long cisco_banner (aka server_banner) field.
EPSS 4.74% · 89.6th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
4.74%
89.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| xelerance | openswan | 2.6.27, 2.6.28, 2.6.26 |
| n/a | n/a | n/a |
Timeline
- Oct 5, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 14, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://secunia.com/advisories/41769 technical
- ADV-2010-2526 vdb
- 43588 vdb
- RHSA-2010:0892 vendor-advisory
- 1024749 vdb
- http://www.openswan.org/download/CVE-2010-3308/openswan-2.6.26-2.6.28-CVE-2010-330x.patch url
- FEDORA-2010-15508 vendor-advisory
- FEDORA-2010-15381 vendor-advisory
- FEDORA-2010-15516 vendor-advisory
- http://www.openswan.org/download/CVE-2010-3308/CVE-2010-3308.txt url
- https://nvd.nist.gov/vuln/detail/CVE-2010-3308 advisory
- https://access.redhat.com/errata/RHSA-2010:0892 url
- https://access.redhat.com/security/cve/CVE-2010-3308 url
- https://bugzilla.redhat.com/show_bug.cgi?id=637924 url