Blog

Release and vulnerability announcements for strongSwan

A vulnerability in the eap-peap and eap-ttls plugins related to the propagation of authentication details from inner EAP methods was discovered in strongSwan that can result in incorrect identity binding and potential authorization bypass. All versions since 4.5.0 are affected.

A vulnerability in the x509 plugin related to the parsing of the ietfAttrSyntax ASN.1 type in X.509 attribute certificates was discovered in strongSwan that can lead to a denial of service. All versions since 5.1.3 are affected.

A vulnerability in the x509 plugin related to the parsing of identities in X.509 attribute certificates was discovered in strongSwan that can lead to a denial of service via memory exhaustion. All versions since 4.2.0 are affected.

A vulnerability in libcharon related to the logging of IKE messages was discovered in strongSwan that can result in a denial of service via memory exhaustion. All versions since 4.1.2 are affected.

A vulnerability in libstrongswan related to the processing of encrypted PKCS#7 containers was discovered in strongSwan that can result in a denial of service. All versions since 4.6.2 are affected.

A vulnerability in the x509 plugin related to the verification of X.509 attribute certificates was discovered in strongSwan that can lead to a denial of service. All versions since 4.2.0 are affected.

A vulnerability in the openssl plugin related to the processing of PKCS#7 containers was discovered in strongSwan that can result in a crash. All versions since 5.0.2 are affected.

A vulnerability in the eap-aka plugin related to processing an unexpected AKA-Synchronization-Failure message was discovered in strongSwan that can result in a crash. All versions since 4.1.10 are affected.