Debian Security Advisory

DLA-1528-1 strongswan -- LTS security update

Date Reported:
02 Oct 2018
Affected Packages:
strongswan
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-17540.
More information:

It was discovered that there was a denial-of-service vulnerability in strongswan, a virtual private network (VPN) client and server.

Verification of an RSA signature with a very short public key caused an integer underflow in a length check that resulted in a heap buffer overflow.

For Debian 8 Jessie, this issue has been fixed in strongswan version 5.2.1-6+deb8u8.

We recommend that you upgrade your strongswan packages.