VYPR

rpm package

suse/strongswan&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1

pkg:rpm/suse/strongswan&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1

Vulnerabilities (6)

  • CVE-2018-17540HigOct 3, 2018
    affected < 5.1.3-26.13.1fixed 5.1.3-26.13.1

    The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.

  • CVE-2018-16152HigSep 26, 2018
    affected < 5.1.3-26.13.1fixed 5.1.3-26.13.1

    In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a re

  • CVE-2018-16151HigSep 26, 2018
    affected < 5.1.3-26.13.1fixed 5.1.3-26.13.1

    In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification. Similar to the flaw in the

  • CVE-2018-10811HigJun 19, 2018
    affected < 5.1.3-26.13.1fixed 5.1.3-26.13.1

    strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

  • CVE-2018-5388MedMay 31, 2018
    affected < 5.1.3-26.13.1fixed 5.1.3-26.13.1

    In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

  • CVE-2015-8023Nov 18, 2015
    affected < 5.1.3-22.1fixed 5.1.3-22.1

    The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Ch