Memory corruption in strongSwan - CVE-2018-10811

 

Memory corruption in strongSwan - CVE-2018-10811

Published: May 31, 2018 / Updated: June 1, 2018


Vulnerability identifier: #VU13125
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10811
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists in the Internet Key Exchange Version 2 (IKEv2) key derivation of strongSwan due to insufficient initialization of the variable that stores the SKEYSEED for IKEv2 key derivation before using the negotiated pseudorandom function (PRF). A remote attacker can trigger a key derivation failure and cause the affected software to clear the uninitialized memory that may lead to crash.


Affected software

strongSwan
Gentoo Linux
Debian Linux
Fedora
Opensuse
strongswan (Alpine package)
strongswan
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru

How to mitigate CVE-2018-10811

Update to version 5.6.3.

strongswan (Alpine package) - update to 5.6.3-r0
strongswan - addressed in versions 5.6.3-1.el7, 5.6.3-1.fc28
Flex System FC3171 8Gb SAN Switch - update to 9.1.15.01.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.15.01.00

External References

Related Security Bulletins