Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 41 results


CVE-2021-41991

Medium priority
Fixed

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code...

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-41990

Medium priority
Fixed

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator....

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2018-17540

Medium priority
Fixed

The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-16152

Medium priority
Fixed

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field...

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-16151

Medium priority
Fixed

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5...

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-5389

Low priority
Ignored

The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well...

4 affected packages

ipsec-tools, isakmpd, libreswan, strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ipsec-tools Not in release Not in release Ignored Ignored
isakmpd Ignored Ignored Ignored Ignored
libreswan Ignored Ignored Ignored Not in release
strongswan Ignored Ignored Ignored Ignored
Show less packages

CVE-2018-5388

Low priority

Some fixes available 3 of 4

In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-10811

Low priority

Some fixes available 3 of 4

strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed Fixed
Show less packages

CVE-2018-6459

Medium priority
Not affected

The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation...

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Not affected
Show less packages

CVE-2017-11185

Medium priority
Fixed

The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.

1 affected packages

strongswan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
strongswan Fixed
Show less packages