[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5249-1 strongswan -- strongswan

ID: oval:org.secpod.oval:def:88411Date: (C)2023-03-28   (M)2023-11-13
Class: PATCHFamily: unix




Lahav Schlesinger discovered a vulnerability in the revocation plugin of strongSwan, an IKE/IPsec suite. The revocation plugin uses OCSP URIs and CRL distribution points which come from certificates provided by the remote endpoint. The plugin didn"t check for the certificate chain of trust before using those URIs, so an attacker could provided a crafted certificate containing URIs pointing to servers under their control, potentially leading to denial-of-service attacks.

Platform:
Linux Mint 5
Product:
libcharon-extra-plugins
libstrongswan
libcharon-extauth-plugins
charon-systemd
strongswan
charon-cmd
Reference:
DSA-5249-1
CVE-2022-40617
CVE    1
CVE-2022-40617
CPE    7
cpe:/a:strongswan:libstrongswan
cpe:/a:strongswan:strongswan
cpe:/a:charon-systemd:charon-systemd
cpe:/a:libcharon-extra-plugins:libcharon-extra-plugins
...

© SecPod Technologies