OESA-2021-1408
Dashboard / Vulnerabilities / OESA-2021-1408
OESA-2021-1408
Summary: strongswan security update
Details: The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel. Security Fix(es): The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.(CVE-2021-41990) The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.(CVE-2021-41991)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1408, https://nvd.nist.gov/vuln/detail/CVE-2021-41990, https://nvd.nist.gov/vuln/detail/CVE-2021-41991
Affected packages
Package
Name: strongswan
Purl: pkg:rpm/openEuler/strongswan&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
