Buffer underflow in strongSwan - CVE-2018-5388

 

Buffer underflow in strongSwan - CVE-2018-5388

Published: May 26, 2018 / Updated: May 29, 2018


Vulnerability identifier: #VU13024
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5388
CWE-ID: CWE-124
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to buffer underflow stroke_socket.c while improper checking of packet length. A local attacker can submit specially crafted packets, trigger resource exhaustion and cause the service to crash while reading from the socket.


Affected software

strongSwan
Arch Linux
Debian Linux
Gentoo Linux
Fedora
Opensuse
strongswan (Alpine package)
strongswan

How to mitigate CVE-2018-5388

Update to version 5.6.2.

strongswan (Alpine package) - update to 5.6.3-r0
strongswan - addressed in versions 5.6.2-6.el7, 5.6.2-6.fc27, 5.6.2-6.fc28, 5.6.3-1.el7

External References

Related Security Bulletins