Buffer overflow in strongSwan - CVE-2018-17540
Published: October 7, 2018
Vulnerability identifier: #VU15165
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17540
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service attacks.
The vulnerability exists due to a boundary error when processing certificates within gmp plugin. A remote attacker can create a specially crafted certificate, pass it to the affected application and trigger application crash.
Affected software
strongSwan
Gentoo Linux
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
Opensuse
strongswan (Alpine package)
strongswan (Debian package)
strongswan
strongswan-doc
strongswan-debuginfo
strongswan-debugsource
Gentoo Linux
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
Opensuse
strongswan (Alpine package)
strongswan (Debian package)
strongswan
strongswan-doc
strongswan-debuginfo
strongswan-debugsource
How to mitigate CVE-2018-17540
Install updates from vendor's website.
strongSwan - update to 5.7.1
strongswan (Alpine package) - update to 5.5.3-r3
strongswan (Debian package) - update to 5.5.1-4+deb9u4
strongswan - update to 4.4.0-6.36.12.1
strongswan-doc - update to 4.4.0-6.36.12.1
strongswan-debuginfo - update to 4.4.0-6.36.12.1
strongswan-debugsource - update to 4.4.0-6.36.12.1
strongswan (Alpine package) - update to 5.5.3-r3
strongswan (Debian package) - update to 5.5.1-4+deb9u4
strongswan - update to 4.4.0-6.36.12.1
strongswan-doc - update to 4.4.0-6.36.12.1
strongswan-debuginfo - update to 4.4.0-6.36.12.1
strongswan-debugsource - update to 4.4.0-6.36.12.1