rpm package
suse/strongswan&distro=SUSE Linux Enterprise Server for SAP Applications 11 SP4
pkg:rpm/suse/strongswan&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-11185 | Hig | 7.5 | < 4.4.0-6.36.3.1 | 4.4.0-6.36.3.1 | Aug 18, 2017 | The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature. | |
| CVE-2017-9023 | Hig | 7.5 | < 4.4.0-6.35.1 | 4.4.0-6.35.1 | Jun 8, 2017 | The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate. | |
| CVE-2017-9022 | Hig | 7.5 | < 4.4.0-6.35.1 | 4.4.0-6.35.1 | Jun 8, 2017 | The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate. | |
| CVE-2015-8023 | — | < 4.4.0-6.32.1 | 4.4.0-6.32.1 | Nov 18, 2015 | The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Ch | ||
| CVE-2015-4171 | — | < 4.4.0-6.29.2 | 4.4.0-6.29.2 | Jun 10, 2015 | strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote |
- affected < 4.4.0-6.36.3.1fixed 4.4.0-6.36.3.1
The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.
- affected < 4.4.0-6.35.1fixed 4.4.0-6.35.1
The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.
- affected < 4.4.0-6.35.1fixed 4.4.0-6.35.1
The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
- CVE-2015-8023Nov 18, 2015affected < 4.4.0-6.32.1fixed 4.4.0-6.32.1
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Ch
- CVE-2015-4171Jun 10, 2015affected < 4.4.0-6.29.2fixed 4.4.0-6.29.2
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote