> Search  

Software is not perfect. Xelerance corporation attempts to provide the highest quality products possible. We do this by attempting to get complete test coverage for the code. This goal is not yet attained.

Should you need to report a possible vulnerability in openswan, we would ask that you contact us privately first. You can email us at: security (at) xelerance.com.

We would ask that you encrypt the email with GPG/PGP if possible, and provide us with serveral ways of securely contacting you. We will respect any request to remain confidential.

The GPG key to use is here, on the key servers, and is available via finger.

Publically disclosed vulnerabilities

DateIDVulnerabilityFixed in
2005-11-14CVE-2005-3671PROTOS ISAKMP Test Suite DoS attackopenswan 2.4.2 (bug #1) and 2.4.4 (bug #2)
2005-01-26CAN-2005-0162Openswan XAUTH/PAM Buffer Overflow Vulnerabilityopenswan 1.0.9, 2.2.1 and 2.3.0
2004-06-28CAN-2004-0590Certificate chain authentication in Openswan plutoopenswan 1.0.6 and 2.1.4

Sponsored by:
Xelerance
© 2003-2006 Xelerance Corporation