The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1760-1 New openswan packages fix denial of service
EUVD EUVD EUVD-2008-4173 The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T10:08:34.945Z

Reserved: 2008-09-23T00:00:00

Link: CVE-2008-4190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2008-09-24T11:42:25.250

Modified: 2025-04-09T00:30:58.490

Link: CVE-2008-4190

cve-icon Redhat

Severity : Low

Publid Date: 2008-08-24T00:00:00Z

Links: CVE-2008-4190 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses