strongswan -- multiple vulnerabilities
strongSwan security team reports:
- RSA public keys passed to the gmp plugin aren't validated sufficiently
before attempting signature verification, so that invalid input might
lead to a floating point exception. [CVE-2017-9022]
- ASN.1 CHOICE types are not correctly handled by the ASN.1 parser when
parsing X.509 certificates with extensions that use such types. This
could lead to infinite looping of the thread parsing a specifically crafted certificate.
Copyright © 2003-2005 Jacques Vidrine and contributors.
Please see the source of this document for full copyright