Description
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4989-1 | strongswan security update |
EUVD |
EUVD-2021-28980 | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. |
Ubuntu USN |
USN-5111-1 | strongSwan vulnerabilities |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Siemens
Subscribe
6gk5615-0aa00-2aa2
Subscribe
6gk5615-0aa00-2aa2 Firmware
Subscribe
6gk5804-0ap00-2aa2
Subscribe
6gk5804-0ap00-2aa2 Firmware
Subscribe
6gk5812-1aa00-2aa2
Subscribe
6gk5812-1aa00-2aa2 Firmware
Subscribe
6gk5812-1ba00-2aa2
Subscribe
6gk5812-1ba00-2aa2 Firmware
Subscribe
6gk5816-1aa00-2aa2
Subscribe
6gk5816-1aa00-2aa2 Firmware
Subscribe
6gk5816-1ba00-2aa2
Subscribe
6gk5816-1ba00-2aa2 Firmware
Subscribe
6gk5826-2ab00-2ab2
Subscribe
6gk5826-2ab00-2ab2 Firmware
Subscribe
6gk5856-2ea00-3aa1
Subscribe
6gk5856-2ea00-3aa1 Firmware
Subscribe
6gk5856-2ea00-3da1
Subscribe
6gk5856-2ea00-3da1 Firmware
Subscribe
6gk5874-2aa00-2aa2
Subscribe
6gk5874-2aa00-2aa2 Firmware
Subscribe
6gk5874-3aa00-2aa2
Subscribe
6gk5874-3aa00-2aa2 Firmware
Subscribe
6gk5876-3aa02-2ba2
Subscribe
6gk5876-3aa02-2ba2 Firmware
Subscribe
6gk5876-3aa02-2ea2
Subscribe
6gk5876-3aa02-2ea2 Firmware
Subscribe
6gk5876-4aa00-2ba2
Subscribe
6gk5876-4aa00-2ba2 Firmware
Subscribe
6gk5876-4aa00-2da2
Subscribe
6gk5876-4aa00-2da2 Firmware
Subscribe
6gk6108-4am00-2ba2
Subscribe
6gk6108-4am00-2ba2 Firmware
Subscribe
6gk6108-4am00-2da2
Subscribe
6gk6108-4am00-2da2 Firmware
Subscribe
Strongswan
Subscribe
Strongswan
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:22:25.777Z
Reserved: 2021-10-04T00:00:00.000Z
Link: CVE-2021-41990
No data.
Status : Modified
Published: 2021-10-18T14:15:10.297
Modified: 2024-11-21T06:27:01.873
Link: CVE-2021-41990
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN