StrongSwan 5.9.8

CPE Details

StrongSwan 5.9.8
5.9.8
2022-10-31
12h56 +00:00
2022-10-31
13h19 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:strongswan:strongswan:5.9.8:-:*:*:*:*:*:*

Informations

Vendor

strongswan

Product

strongswan

Version

5.9.8

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-41913 2023-12-06 23h00 +00:00 strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.
9.8
Critical
CVE-2023-26463 2023-04-14 00h00 +00:00 strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is sending an untrusted client certificate during EAP-TLS. A server is affected only if it loads plugins that implement TLS-based EAP methods (EAP-TLS, EAP-TTLS, EAP-PEAP, or EAP-TNC). This is fixed in 5.9.10.
9.8
Critical