UBUNTU-CVE-2021-45079
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-45079
UBUNTU-CVE-2021-45079
Summary:
Details: In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
References: https://ubuntu.com/security/CVE-2021-45079, https://github.com/strongswan/strongswan/releases/tag/5.9.5, https://www.strongswan.org/blog/2022/01/24/strongswan-vulnerability-(cve-2021-45079).html, https://ubuntu.com/security/notices/USN-5250-1, https://ubuntu.com/security/notices/USN-5250-2, https://www.cve.org/CVERecord?id=CVE-2021-45079
Affected packages
Package
Name: strongswan
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
