Description
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2788-1 | strongswan security update |
Debian DSA |
DSA-4989-1 | strongswan security update |
EUVD |
EUVD-2021-28981 | The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility. |
Ubuntu USN |
USN-5111-1 | strongSwan vulnerabilities |
Ubuntu USN |
USN-5111-2 | strongSwan vulnerability |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Siemens
Subscribe
Cp 1543-1
Subscribe
Cp 1543-1 Firmware
Subscribe
Scalance Sc622-2c
Subscribe
Scalance Sc622-2c Firmware
Subscribe
Scalance Sc632-2c
Subscribe
Scalance Sc632-2c Firmware
Subscribe
Scalance Sc636-2c
Subscribe
Scalance Sc636-2c Firmware
Subscribe
Scalance Sc642-2c
Subscribe
Scalance Sc642-2c Firmware
Subscribe
Scalance Sc646-2c
Subscribe
Scalance Sc646-2c Firmware
Subscribe
Simatic Cp 1242-7 Gprs V2
Subscribe
Simatic Cp 1242-7 Gprs V2 Firmware
Subscribe
Simatic Cp 1243-1
Subscribe
Simatic Cp 1243-1 Firmware
Subscribe
Simatic Cp 1243-7 Lte\/us
Subscribe
Simatic Cp 1243-7 Lte\/us Firmware
Subscribe
Simatic Cp 1542sp-1
Subscribe
Simatic Cp 1542sp-1 Firmware
Subscribe
Simatic Cp 1542sp-1 Irc
Subscribe
Simatic Cp 1542sp-1 Irc Firmware
Subscribe
Simatic Cp 1543sp-1
Subscribe
Simatic Cp 1543sp-1 Firmware
Subscribe
Simatic Net Cp1243-7 Lte Eu
Subscribe
Simatic Net Cp1243-7 Lte Eu Firmware
Subscribe
Simatic Net Cp 1243-8 Irc
Subscribe
Simatic Net Cp 1243-8 Irc Firmware
Subscribe
Simatic Net Cp 1545-1
Subscribe
Simatic Net Cp 1545-1 Firmware
Subscribe
Sinema Remote Connect Server
Subscribe
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail
Subscribe
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware
Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec
Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Firmware
Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail
Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware
Subscribe
Siplus Net Cp 1543-1
Subscribe
Siplus Net Cp 1543-1 Firmware
Subscribe
Siplus S7-1200 Cp 1243-1
Subscribe
Siplus S7-1200 Cp 1243-1 Firmware
Subscribe
Siplus S7-1200 Cp 1243-1 Rail
Subscribe
Siplus S7-1200 Cp 1243-1 Rail Firmware
Subscribe
Strongswan
Subscribe
Strongswan
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:22:25.655Z
Reserved: 2021-10-04T00:00:00.000Z
Link: CVE-2021-41991
No data.
Status : Modified
Published: 2021-10-18T14:15:10.333
Modified: 2024-11-21T06:27:02.090
Link: CVE-2021-41991
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN