Description
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Published: 2021-10-18
Score: 7.5 High
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-4989-1 strongswan security update
EUVD EUVD EUVD-2021-28980 The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Ubuntu USN Ubuntu USN USN-5111-1 strongSwan vulnerabilities
History

No history.

Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Siemens 6gk5615-0aa00-2aa2 6gk5615-0aa00-2aa2 Firmware 6gk5804-0ap00-2aa2 6gk5804-0ap00-2aa2 Firmware 6gk5812-1aa00-2aa2 6gk5812-1aa00-2aa2 Firmware 6gk5812-1ba00-2aa2 6gk5812-1ba00-2aa2 Firmware 6gk5816-1aa00-2aa2 6gk5816-1aa00-2aa2 Firmware 6gk5816-1ba00-2aa2 6gk5816-1ba00-2aa2 Firmware 6gk5826-2ab00-2ab2 6gk5826-2ab00-2ab2 Firmware 6gk5856-2ea00-3aa1 6gk5856-2ea00-3aa1 Firmware 6gk5856-2ea00-3da1 6gk5856-2ea00-3da1 Firmware 6gk5874-2aa00-2aa2 6gk5874-2aa00-2aa2 Firmware 6gk5874-3aa00-2aa2 6gk5874-3aa00-2aa2 Firmware 6gk5876-3aa02-2ba2 6gk5876-3aa02-2ba2 Firmware 6gk5876-3aa02-2ea2 6gk5876-3aa02-2ea2 Firmware 6gk5876-4aa00-2ba2 6gk5876-4aa00-2ba2 Firmware 6gk5876-4aa00-2da2 6gk5876-4aa00-2da2 Firmware 6gk6108-4am00-2ba2 6gk6108-4am00-2ba2 Firmware 6gk6108-4am00-2da2 6gk6108-4am00-2da2 Firmware
Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:22:25.777Z

Reserved: 2021-10-04T00:00:00.000Z

Link: CVE-2021-41990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-18T14:15:10.297

Modified: 2024-11-21T06:27:01.873

Link: CVE-2021-41990

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-10-18T00:00:00Z

Links: CVE-2021-41990 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses