Search CVE reports


Toggle filters

11 – 20 of 41 results


CVE-2021-41991

Medium priority
Fixed

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code...

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-41990

Medium priority
Fixed

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator....

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2018-17540

Medium priority
Fixed

The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-16152

Medium priority
Fixed

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field...

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-16151

Medium priority
Fixed

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5...

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-5389

Low priority
Ignored

The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well...

4 affected packages

ipsec-tools, isakmpd, libreswan, strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ipsec-tools Not in release Not in release Ignored Ignored
isakmpd Ignored Ignored Ignored Ignored
libreswan Ignored Ignored Ignored Not in release
strongswan Ignored Ignored Ignored Ignored
Show less packages

CVE-2018-5388

Low priority

Some fixes available 3 of 4

In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-10811

Low priority

Some fixes available 3 of 4

strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-6459

Medium priority
Not affected

The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation...

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Not affected
Show less packages

CVE-2017-11185

Medium priority
Fixed

The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.

1 affected package

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed
Show less packages