Improper input validation - CVE-2017-9023
Published: May 31, 2017 / Updated: June 2, 2017
Vulnerability identifier: #VU6874
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9023
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
ASN.1 CHOICE types are not correctly handled by the ASN.1 parser in strongSwan when
parsing X.509 certificates with extensions that use such types. This could
lead to infinite looping of the thread parsing a specifically crafted
certificate.
Affected software
Debian Linux
SUSE Linux
Ubuntu
strongswan (Alpine package)
SUSE Linux
Ubuntu
strongswan (Alpine package)
How to mitigate CVE-2017-9023
Install update from vendor's website.
strongswan (Alpine package) - update to 5.3.5-r2