Hash: SHA256

Package        : strongswan
Version        : 4.5.2-1.5+deb7u10
CVE ID         : CVE-2017-11185
Debian Bug     : #872155

It was discovered that there was a denial-of-service vulnerability in
the Strongswan Virtual Private Network (VPN) software.

Specific RSA signatures passed to the gmp plugin for verification could
cause a null-pointer dereference. Potential triggers are signatures in
certificates, but also signatures used during IKE authentication.

For more details, please see:

  


For Debian 7 "Wheezy", this issue has been fixed in strongswan version
4.5.2-1.5+deb7u10.

We recommend that you upgrade your strongswan packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1059-1: strongswan security update

August 18, 2017
It was discovered that there was a denial-of-service vulnerability in the Strongswan Virtual Private Network (VPN) software

Summary

Specific RSA signatures passed to the gmp plugin for verification could
cause a null-pointer dereference. Potential triggers are signatures in
certificates, but also signatures used during IKE authentication.

For more details, please see:




For Debian 7 "Wheezy", this issue has been fixed in strongswan version
4.5.2-1.5+deb7u10.

We recommend that you upgrade your strongswan packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : strongswan
Version : 4.5.2-1.5+deb7u10
CVE ID : CVE-2017-11185
Debian Bug : #872155

Related News