CVE-2008-4190
Openswan - Symlink Following
Title source: ruleDescription
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.
Exploits (1)
References (15)
Scores
EPSS
0.0017
EPSS Percentile
38.5%
Details
CWE
CWE-59
Status
published
Products (31)
openswan/openswan
1.0.4
openswan/openswan
1.0.5
openswan/openswan
1.0.6
openswan/openswan
1.0.7
openswan/openswan
1.0.8
openswan/openswan
1.0.9
openswan/openswan
2.1.1
openswan/openswan
2.1.2
openswan/openswan
2.1.4
openswan/openswan
2.1.5
... and 21 more
Published
Sep 24, 2008
Tracked Since
Feb 18, 2026