OESA-2022-1525
Dashboard / Vulnerabilities / OESA-2022-1525
Summary: strongswan security update
Details: The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel. Security Fix(es): In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.(CVE-2021-45079)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1525, https://nvd.nist.gov/vuln/detail/CVE-2021-45079
Affected packages
Package
Name: strongswan
Purl: pkg:rpm/openEuler/strongswan&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
