Blog

Release and vulnerability announcements for strongSwan

A denial-of-service vulnerability in the gmp plugin was discovered in strongSwan. All versions since 4.4.0 are affected.

A denial-of-service vulnerability in the x509 plugin was discovered in strongSwan. All versions are affected.

We are happy to announce the release of strongSwan 5.3.5, which fixes a regression in 5.3.4.

An authentication bypass vulnerability in the eap-mschapv2 plugin was discovered in strongSwan. All versions since 4.2.12 are affected.

We are happy to announce the release of strongSwan 5.3.4, which fixes a vulnerability and several other issues.

We are happy to announce the release of strongSwan 5.3.3, which brings support for the ChaCha20/Poly1305 AEAD cipher, configuration of auxiliary CA information such as CRL and OCSP URIs via VICI, and adds numerous other new features and fixes.

An information leak vulnerability that affects certain IKEv2 setups was discovered in strongSwan. All versions since 4.3.0 are affected.

We are happy to announce the release of strongSwan 5.3.2, which fixes a vulnerability and two other issues.