Strongswan

Strongswan

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.65%
  • Veröffentlicht 18.10.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 06:27:01

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution ...

  • EPSS 0.51%
  • Veröffentlicht 12.06.2019 14:29:02
  • Zuletzt bearbeitet 21.11.2024 04:18:32

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check v...

  • EPSS 3.51%
  • Veröffentlicht 03.10.2018 20:29:09
  • Zuletzt bearbeitet 21.11.2024 03:54:34

The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.

  • EPSS 1.89%
  • Veröffentlicht 26.09.2018 21:29:01
  • Zuletzt bearbeitet 03.12.2025 21:15:50

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature ve...

  • EPSS 1.89%
  • Veröffentlicht 26.09.2018 21:29:01
  • Zuletzt bearbeitet 03.12.2025 21:15:50

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verificati...

  • EPSS 6.2%
  • Veröffentlicht 19.06.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:04

strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

  • EPSS 3.97%
  • Veröffentlicht 31.05.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:43

In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

  • EPSS 1.05%
  • Veröffentlicht 20.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:42

The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter.

  • EPSS 4.52%
  • Veröffentlicht 07.09.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.

  • EPSS 2.83%
  • Veröffentlicht 18.08.2017 17:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.