CVE-2009-2661
Estado: ModificadaMedia (5)—
The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.58%
- Percentil entre todas las CVEs puntuadas: 75
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
- http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.3.x_asn1_length.patch
- http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.x.x_asn1_length.patch
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html
- http://secunia.com/advisories/36922
- http://up2date.astaro.com/2009/08/up2date_7505_released.html
- http://www.debian.org/security/2009/dsa-1899
- http://www.openwall.com/lists/oss-security/2009/07/27/1
- http://www.vupen.com/english/advisories/2009/2247
- https://lists.strongswan.org/pipermail/announce/2009-July/000056.html
- http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.3.x_asn1_length.patch
- http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.x.x_asn1_length.patch
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html
- http://secunia.com/advisories/36922
- http://up2date.astaro.com/2009/08/up2date_7505_released.html
- http://www.debian.org/security/2009/dsa-1899
- http://www.openwall.com/lists/oss-security/2009/07/27/1
- http://www.vupen.com/english/advisories/2009/2247
- https://lists.strongswan.org/pipermail/announce/2009-July/000056.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-2661",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-08-04T16:30:00.483",
"references": [
{
"url": "http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.3.x_asn1_length.patch",
"source": "cve@mitre.org"
},
{
"url": "http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.x.x_asn1_length.patch",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/36922",
"source": "cve@mitre.org"
},
{
"url": "http://up2date.astaro.com/2009/08/up2date_7505_released.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2009/dsa-1899",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2009/07/27/1",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/2247",
"source": "cve@mitre.org"
},
{
"url": "https://lists.strongswan.org/pipermail/announce/2009-July/000056.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.3.x_asn1_length.patch",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.x.x_asn1_length.patch",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/36922",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://up2date.astaro.com/2009/08/up2date_7505_released.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2009/dsa-1899",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2009/07/27/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2009/2247",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.strongswan.org/pipermail/announce/2009-July/000056.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185."
},
{
"lang": "es",
"value": "La función asn1_length en strongSwan 2.8 antes de 2.8.11, 4.2 antes de 4.2.17 y 4.3 antes de 4.3.3 no maneja adecuadamente certificados X.509 con Relative Distinguished Names (RDNs) modificados, lo que permite a atacantes remotos provocar una denegación de servicio (caída del demonio pluto IKE) mediante datos ASN.1 malformados. NOTA: Esto es debido a una solución incompleta de CVE-2009-2185."
}
],
"lastModified": "2026-06-16T23:09:56.540",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5518A917-D5D1-4985-BF71-B1A34BD3D5B4"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "778D7442-F54A-47DF-B87B-3CFA3CF08799"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A4B1F28-B3B8-4E31-8E4E-25F5A29F3AB3"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16984E6E-7CA8-4DC3-B800-FFE007617FE4"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C85F0BE-7E89-4B79-A036-9238785BE705"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DFF4780-2F92-4DF3-878A-C7E2BD57E39C"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C794994-9367-4BBB-8940-BBB44B7C1C5F"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "082272D3-0FE4-4959-978A-FFF795B52CA3"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DFEF9B3-C7F7-4588-A174-FAFD39C04116"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:2.8.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E18EB62-1042-4F26-9EC3-B7EEA2182716"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97027262-849C-4DE9-90C9-0D9FBBC9F96B"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8658539D-27D8-47EE-9468-A6B625E6D45F"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89ACA351-D10F-4D1A-95B0-4B2E329F1E1A"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A4D6E89-5313-4016-8A7E-036579330DB6"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C41F9E10-000D-4F3B-BEA6-DEE87405B89B"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F37DFE8-2996-4904-B733-7BAECA95CB48"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38209DC9-3BE6-49EF-8BA1-6E2BC5D24FEF"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "155EB8F5-7C3C-4293-91EE-62DA561DA54A"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E42B67A3-8650-426F-A8E8-DCA4180D787A"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21CDA326-C5E4-4BAF-9DC6-4E5A57304C1F"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.2.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7AF119CF-2CC5-4313-8722-06BCE3DC6255"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "384C0CAE-8AC3-47AA-9F1C-9DE6779CA583"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00BC4DA6-BFD1-43CF-B8B8-DACBF09E4721"
},
{
"criteria": "cpe:2.3:a:strongswan:strongswan:4.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FEDBF811-7E48-4E99-AE05-FFC12AAF1CDF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}