strongswan: denial of service flaw in 5.0.3/5.0.4
Published Aug 28, 2013
4.3
MEDIUMCVSS 2.0
EPSS 2.99%
Description
The is_asn1 function in strongSwan 4.1.11 through 5.0.4 does not properly validate the return value of the asn1_length function, which allows remote attackers to cause a denial of service (segmentation fault) via a (1) XAuth username, (2) EAP identity, or (3) PEM encoded file that starts with a 0x04, 0x30, or 0x31 character followed by an ASN.1 length value that triggers an integer overflow.
Affected products
No data.
Configuration 1
- 4.1.11
Configuration 2
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
No data.
Red Hat Enterprise Linux 5
openswan
Not affected
Red Hat Enterprise Linux 6
openswan
Not affected
Red Hat Enterprise Linux 7
openswan
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openswan | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openswan | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openswan | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of openswan as shipped with Red Hat Enterprise Linux 5 or 6 as they did not include the problematic newline checks when validating ASN.1 length.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 2.99% (0.02985) | 86.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.99% (0.02985) | 85.51th | v5 (v2026.06.15) |
| Mar 30, 2025 | 2.90% (0.02902) | 85.12th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.28% (0.08277) | 86.82th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.90% (0.02902) | 85.43th | v4 (v2025.03.14) |
| Dec 12, 2024 | 4.21% (0.04205) | 92.55th | v3 (v2023.03.01) |
| May 15, 2024 | 4.21% (0.04205) | 92.19th | v3 (v2023.03.01) |
| Apr 10, 2023 | 3.58% (0.03577) | 90.21th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.61% (0.03610) | 90.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.78% (0.01776) | 76.86th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.78% (0.01776) | 76.81th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.78% (0.01776) | 74.78th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.78% (0.01776) | 53.99th | v2 (v2022.01.01) |
References (14)
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00022.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00050.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/54315 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/54524 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://strongswan.org/blog/2013/08/01/strongswan-5.1.0-released.html x_refsource_CONFIRMVendor Advisory
- http://strongswan.org/blog/2013/08/01/strongswan-denial-of-service-vulnerability-%28cve-2013-5018%29.html x_refsource_CONFIRMVendor Advisory
- http://strongswan.org/blog/2013/08/01/strongswan-denial-of-service-vulnerability-(cve-2013-5018).html
- http://www.securityfocus.com/bid/61564 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-5018 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=991215 Issue Tracking
- https://lists.strongswan.org/pipermail/users/2013-July/009540.html mailing-listx_refsource_MLISTExploit
- https://nvd.nist.gov/vuln/detail/CVE-2013-5018
- https://www.cve.org/CVERecord?id=CVE-2013-5018
Change history (0)
No recorded changes yet.