CVE-2008-4190
Last modified
CVE-2008-4190 is a vulnerability of currently unknown severity. The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openswan | Openswan | 1.0.4 |
| Openswan | Openswan | 1.0.5 |
| Openswan | Openswan | 1.0.6 |
| Openswan | Openswan | 1.0.7 |
| Openswan | Openswan | 1.0.8 |
| Openswan | Openswan | 1.0.9 |
| Openswan | Openswan | 2.1.1 |
| Openswan | Openswan | 2.1.2 |
| Openswan | Openswan | 2.1.4 |
| Openswan | Openswan | 2.1.5 |
| Openswan | Openswan | 2.1.6 |
| Openswan | Openswan | 2.2 |
| Openswan | Openswan | 2.3 |
| Xelerance | Openswan | 2.3.1 |
| Xelerance | Openswan | 2.4.0 |
| Xelerance | Openswan | 2.4.2 |
| Xelerance | Openswan | 2.4.4 |
| Xelerance | Openswan | 2.6.03 |
| Xelerance | Openswan | 2.6.04 |
| Xelerance | Openswan | 2.6.05 |
| Xelerance | Openswan | 2.6.06 |
| Xelerance | Openswan | 2.6.07 |
| Xelerance | Openswan | 2.6.08 |
| Xelerance | Openswan | 2.6.09 |
| Xelerance | Openswan | 2.6.10 |
| Xelerance | Openswan | 2.6.11 |
| Xelerance | Openswan | 2.6.12 |
| Xelerance | Openswan | 2.6.13 |
| Xelerance | Openswan | 2.6.14 |
| Xelerance | Openswan | 2.6.15 |
| Xelerance | Openswan | 2.6.16 |
References
- http://secunia.com/advisories/34182Vendor Advisory
- http://secunia.com/advisories/34472Vendor Advisory
- http://secunia.com/advisories/34182Vendor Advisory
- http://secunia.com/advisories/34472Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4190?
How severe is CVE-2008-4190?
How do I fix CVE-2008-4190?
Are you affected by CVE-2008-4190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
