CVE-2017-9022
08.06.2017, 16:29
The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| strongswan | strongswan | 𝑥 ≤ 5.5.2 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 16.10 |
| canonical | ubuntu_linux | 17.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| strongswan |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| strongswan-doc |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| strongswan-hmac |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| strongswan-ipsec |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| strongswan-libs0 |
|
Common Weakness Enumeration
References