[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5056-1 strongswan -- strongswan

ID: oval:org.secpod.oval:def:605777Date: (C)2022-02-04   (M)2023-11-13
Class: PATCHFamily: unix




Zhuowei Zhang discovered a bug in the EAP authentication client code of strongSwan, an IKE/IPsec suite, that may allow to bypass the client and in some scenarios even the server authentication, or could lead to a denial-of-service attack. When using EAP authentication , the successful completion of the authentication is indicated by an EAP-Success message sent by the server to the client. strongSwan"s EAP client code handled early EAP-Success messages incorrectly, either crashing the IKE daemon or concluding the EAP method prematurely. End result depend on the used configuration, more details can be found in upstream advisory at https://www.strongswan.org/blog/2022/01/24/strongswan-vulnerability-.html

Platform:
Debian 10.x
Debian 11.x
Product:
strongswan
charon-cmd
charon-systemd
libcharon-extauth-plugins
libcharon-extra-plugins
libstrongswan
Reference:
DSA-5056-1
CVE-2021-45079
CVE    1
CVE-2021-45079
CPE    8
cpe:/o:debian:debian_linux:10.x
cpe:/a:strongswan:libstrongswan
cpe:/a:strongswan:strongswan
cpe:/o:debian:debian_linux:11.x
...

© SecPod Technologies