The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-strongswan | Mar 26, 2024 | Oct 18, 2021 | |
| Debian | debian-upgrade-strongswan | Nov 29, 2021 | Oct 18, 2021 | |
| Dell Powerstore Dsa2023173 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Jun 21, 2023 | |
| Freebsd | freebsd-upgrade-package-strongswan | Nov 4, 2022 | Jan 25, 2022 | |
| Suse | — | suse-upgrade-strongswansuse-upgrade-strongswan-docsuse-upgrade-strongswan-hmacsuse-upgrade-strongswan-ipsecsuse-upgrade-strongswan-libs0suse-upgrade-strongswan-mysqlsuse-upgrade-strongswan-nmsuse-upgrade-strongswan-sqlite | Oct 20, 2021 | Oct 18, 2021 |
| Ubuntu | ubuntu-upgrade-libstrongswanubuntu-upgrade-strongswan | Oct 20, 2021 | Oct 18, 2021 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Oct 18, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub