VYPR

rpm package

opensuse/strongswan&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/strongswan&distro=openSUSE%20Tumbleweed

Vulnerabilities (35)

  • CVE-2018-6459MedFeb 20, 2018
    affected < 5.9.0-1.9fixed 5.9.0-1.9

    The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter.

  • CVE-2015-3991CriSep 7, 2017
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.

  • CVE-2017-11185HigAug 18, 2017
    affected < 5.9.0-1.9fixed 5.9.0-1.9

    The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.

  • CVE-2017-9023HigJun 8, 2017
    affected < 5.9.0-1.9fixed 5.9.0-1.9

    The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

  • CVE-2017-9022HigJun 8, 2017
    affected < 5.9.0-1.9fixed 5.9.0-1.9

    The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

  • CVE-2015-8023Nov 18, 2015
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Ch

  • CVE-2015-4171Jun 10, 2015
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote

  • CVE-2014-9221Jan 7, 2015
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.

  • CVE-2014-2338Apr 16, 2014
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.

  • CVE-2013-6076Nov 2, 2013
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted IKEv1 fragmentation packet.

  • CVE-2013-6075Nov 2, 2013
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypas

  • CVE-2013-5018Aug 28, 2013
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    The is_asn1 function in strongSwan 4.1.11 through 5.0.4 does not properly validate the return value of the asn1_length function, which allows remote attackers to cause a denial of service (segmentation fault) via a (1) XAuth username, (2) EAP identity, or (3) PEM encoded file tha

  • CVE-2013-2944May 2, 2013
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.

  • CVE-2012-2388Jun 27, 2012
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."

  • CVE-2009-0790Apr 1, 2009
    affected < 5.3.5-1.1fixed 5.3.5-1.1

    The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK D

Page 2 of 2