Blog

Release and vulnerability announcements for strongSwan

A DoS vulnerability in strongSwan was discovered, which is triggered by XAuth usernames and EAP identities in versions 5.0.3 and 5.0.4.

strongSwan 5.0.4 fixes a security vulnerability which affects all versions since 4.3.5 if the openssl plugin is used for ECDSA signature verification.

strongSwan 4.6.4 fixes a security vulnerability which affects all versions since 4.2.0 if the gmp plugin is used for RSA signature verification.