CVE-2008-4190

Openswan - Symlink Following

Title source: rule

Description

The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.

Exploits (1)

exploitdb WORKING POC VERIFIED
by nofame · bashlocallinux
https://www.exploit-db.com/exploits/9135

Scores

EPSS 0.0017
EPSS Percentile 38.5%

Details

CWE
CWE-59
Status published
Products (31)
openswan/openswan 1.0.4
openswan/openswan 1.0.5
openswan/openswan 1.0.6
openswan/openswan 1.0.7
openswan/openswan 1.0.8
openswan/openswan 1.0.9
openswan/openswan 2.1.1
openswan/openswan 2.1.2
openswan/openswan 2.1.4
openswan/openswan 2.1.5
... and 21 more
Published Sep 24, 2008
Tracked Since Feb 18, 2026