Buffer underflow in strongSwan - CVE-2018-5388
Published: May 26, 2018 / Updated: May 29, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to buffer underflow stroke_socket.c while improper checking of packet length. A local attacker can submit specially crafted packets, trigger resource exhaustion and cause the service to crash while reading from the socket.
Affected software
Arch Linux
Debian Linux
Gentoo Linux
Fedora
Opensuse
strongswan (Alpine package)
strongswan
How to mitigate CVE-2018-5388
strongswan - addressed in versions 5.6.2-6.el7, 5.6.2-6.fc27, 5.6.2-6.fc28, 5.6.3-1.el7
External References
Related Security Bulletins
- Arch Linux update for strongswan
- Arch Linux update for strongswan
- Debian update for strongswan
- Gentoo update for strongSwan
- OpenSUSE Linux update for strongswan
- Buffer underflow in strongswan (Alpine package)
- Fedora 28 update for strongswan
- Fedora 27 update for strongswan
- Fedora EPEL 7 update for strongswan
- Fedora EPEL 7 update for strongswan