Blog

Release and vulnerability announcements for strongSwan

A vulnerability in libsimaka related to the processing of certain EAP-SIM/AKA attributes was discovered in strongSwan that can result in an infinite loop or a heap-based buffer overflow and potentially remote code execution. All versions since 4.3.6 are affected.

A vulnerability in libstrongswan and the pkcs7 plugin related to the processing of encrypted PKCS#7 containers was discovered in strongSwan that can result in a crash. All versions since 5.0.2 are affected.

A vulnerability in libtls related to the processing of the supported_versions extension in TLS was discovered in strongSwan that can result in an infinite loop. All versions since 5.9.2 are affected.

A vulnerability in the eap-ttls plugin related to processing EAP-TTLS AVPs was discovered in strongSwan that can result in resource exhaustion or a crash. All versions since 4.5.0 are affected.

A vulnerability in the NetworkManager plugin that potentially allows using credentials of other local users was discovered in strongSwan. All versions are affected.

A vulnerability in the eap-mschapv2 plugin related to processing Failure Request packets on the client was discovered in strongSwan that can result in a heap-based buffer overflow and potentially remote code execution. All versions since 4.2.12 are affected.

This advisory reclassifies an old bug in our TLS library as a potential authorization bypass vulnerability in order to get the fix applied to affected distribution packages. The bug is contained in versions 5.9.2 through 5.9.5 and was fixed with 5.9.6, which was released in August 2022.

A vulnerability in charon-tkm related to processing DH public values was discovered in strongSwan that can result in a buffer overflow and potentially remote code execution. All versions since 5.3.0 are affected.