Total vulnerabilities in the database
programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_banner (aka server_banner) field, a different vulnerability than CVE-2010-3308.
Software | From | Fixed in |
---|---|---|
xelerance / openswan | 2.6.26 | 2.6.26.x |
xelerance / openswan | 2.6.27 | 2.6.27.x |
xelerance / openswan | 2.6.28 | 2.6.28.x |