Blog

Release and vulnerability announcements for strongSwan

A vulnerability in the openssl plugin related to the enumeration of certificates in PKCS#7 containers was discovered in strongSwan that can result in memory leaks. All versions since 5.0.2 are affected.

A vulnerability in the eap-aka plugin related to processing an unexpected AKA-Synchronization-Failure message was discovered in strongSwan that can result in a crash. All versions since 4.1.10 are affected.

A vulnerability in libstrongswan related to the processing of encrypted PKCS#7 containers was discovered in strongSwan that can result in a denial of service. All versions since 4.6.2 are affected.

A vulnerability in libstrongswan related to the cloning of certain identities was discovered in strongSwan that can result in a double-free and potentially remote code execution. All versions since 4.3.3 are affected.

We are happy to announce the release of strongSwan 6.0.7, which fixes a vulnerability and comes with several other improvements and fixes.

A vulnerability in the gmp plugin related to RSA decryption was discovered in strongSwan that can result in a crash. All versions since 4.3.2 are affected.

A vulnerability in libradius related to the processing of RADIUS attributes was discovered in strongSwan that can result in an infinite loop or an out-of-bounds read that may cause a crash. All versions since 4.2.14 are affected.

A vulnerability in libtls related to the processing of ECDH public values in TLS < 1.3 was discovered in strongSwan that can result in a crash. All versions since 4.5.0 are affected.