SB2017102324 - NULL pointer dereference in strongswan (Alpine package)
Published: October 23, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2017-11185)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via a crafted RSA signature.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=2710c46b44644c2f597699e01f238d4e13d88b11
- https://git.alpinelinux.org/aports/commit/?id=fae42a57529214cd7ee88738466541ee2f7f3643
- https://git.alpinelinux.org/aports/commit/?id=00fb0c7560c6a359c866f0a65415487c19504ffa
- https://git.alpinelinux.org/aports/commit/?id=a38ad2c5bb69ca57ab8f0060390bea3e410cebe0
- https://git.alpinelinux.org/aports/commit/?id=a4e92d627f1b09c04531c883313a2d4a61fad83d