USN-3771-1
Dashboard / Vulnerabilities / USN-3771-1
USN-3771-1
Summary: strongswan vulnerabilities
Details: It was discovered that strongSwan incorrectly handled IKEv2 key derivation. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2018-10811) Sze Yiu Chau discovered that strongSwan incorrectly handled parsing OIDs in the gmp plugin. A remote attacker could possibly use this issue to bypass authorization. (CVE-2018-16151) Sze Yiu Chau discovered that strongSwan incorrectly handled certain parameters fields in the gmp plugin. A remote attacker could possibly use this issue to bypass authorization. (CVE-2018-16152) It was discovered that strongSwan incorrectly handled the stroke plugin. A local administrator could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2018-5388)
References: https://ubuntu.com/security/notices/USN-3771-1, https://ubuntu.com/security/CVE-2018-5388, https://ubuntu.com/security/CVE-2018-10811, https://ubuntu.com/security/CVE-2018-16151, https://ubuntu.com/security/CVE-2018-16152
Affected packages
Package
Name: strongswan
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
