Improper input validation - CVE-2017-9023

 

Improper input validation - CVE-2017-9023

Published: May 31, 2017 / Updated: June 2, 2017


Vulnerability identifier: #VU6874
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9023
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

ASN.1 CHOICE types are not correctly handled by the ASN.1 parser in strongSwan when parsing X.509 certificates with extensions that use such types. This could lead to infinite looping of the thread parsing a specifically crafted certificate.

Affected software

Debian Linux
SUSE Linux
Ubuntu
strongswan (Alpine package)

How to mitigate CVE-2017-9023

Install update from vendor's website.

strongswan (Alpine package) - update to 5.3.5-r2

External References

Related Security Bulletins