vendor:
Openswan
by:
milw0rm.com
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Openswan
Affected Version From: 2.4.12
Affected Version To: 2.6.16
Patch Exists: Yes
Related CWE: CVE-2008-4190
CPE: a:openswan:openswan
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2009
OpenSwan local root exploit (CVE-2008-4190)
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files.
Mitigation:
Disable the IPSEC livetest tool in Openswan.