Improper Certificate Validation in strongSwan - CVE-2022-40617

 

Improper Certificate Validation in strongSwan - CVE-2022-40617

Published: October 3, 2022


Vulnerability identifier: #VU67813
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40617
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error within the revocation plugin, which uses potentially untrusted OCSP URIs and CRL distribution points (CDP) in certificates. A remote attacker can initiate the IKE_SAs and send crafted certificates that contain URIs pointing to servers under their control. As a result, a remote attacker can perform a denial of service (DoS) attack.


Affected software

strongSwan
Gentoo Linux
Debian Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
SUSE Linux Enterprise Module for Packagehub Subpackages
strongswan
strongswan-debugsource
strongswan-hmac
strongswan-ipsec
strongswan-doc
strongswan-libs0-debuginfo
strongswan-libs0
strongswan-ipsec-debuginfo
strongswan (Ubuntu package)
libstrongswan (Ubuntu package)
strongswan-debuginfo
strongswan-help
strongswan-mysql-debuginfo
strongswan-mysql
strongswan-sqlite-debuginfo
strongswan-sqlite
strongswan-nm-debuginfo
strongswan-nm
strongswan (Debian package)
net-vpn/strongswan

How to mitigate CVE-2022-40617

Install updates from vendor's website.

strongSwan - update to 5.9.8
strongswan - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-debugsource - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-hmac - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-ipsec - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-doc - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-libs0-debuginfo - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-libs0 - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-ipsec-debuginfo - addressed in versions 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan (Ubuntu package) - addressed in versions 5.3.51ubuntu3.8+esm3, 5.6.2-1ubuntu2.9, 5.8.2-1ubuntu3.5, 5.9.5-2ubuntu2.1
libstrongswan (Ubuntu package) - addressed in versions 5.3.51ubuntu3.8+esm3, 5.6.2-1ubuntu2.9, 5.8.2-1ubuntu3.5, 5.9.5-2ubuntu2.1
strongswan - update to 5.7.2-9
strongswan-debugsource - update to 5.7.2-9
strongswan-debuginfo - update to 5.7.2-9
strongswan-help - update to 5.7.2-9
strongswan-mysql-debuginfo - addressed in versions 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-mysql - addressed in versions 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-debuginfo - addressed in versions 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-sqlite-debuginfo - addressed in versions 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-sqlite - addressed in versions 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-nm-debuginfo - addressed in versions 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan-nm - addressed in versions 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3
strongswan (Debian package) - update to 5.9.1-1+deb11u3
strongswan - addressed in versions 5.9.8-1.el8, 5.9.8-1.el9, 5.9.8-1.fc36, 5.9.8-1.fc37
net-vpn/strongswan - update to 5.9.10

External References

Related Security Bulletins