Description
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Published: 2021-10-18
Score: 7.5 High
EPSS: 2.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2788-1 strongswan security update
Debian DSA Debian DSA DSA-4989-1 strongswan security update
EUVD EUVD EUVD-2021-28981 The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Ubuntu USN Ubuntu USN USN-5111-1 strongSwan vulnerabilities
Ubuntu USN Ubuntu USN USN-5111-2 strongSwan vulnerability
History

No history.

Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Siemens Cp 1543-1 Cp 1543-1 Firmware Scalance Sc622-2c Scalance Sc622-2c Firmware Scalance Sc632-2c Scalance Sc632-2c Firmware Scalance Sc636-2c Scalance Sc636-2c Firmware Scalance Sc642-2c Scalance Sc642-2c Firmware Scalance Sc646-2c Scalance Sc646-2c Firmware Simatic Cp 1242-7 Gprs V2 Simatic Cp 1242-7 Gprs V2 Firmware Simatic Cp 1243-1 Simatic Cp 1243-1 Firmware Simatic Cp 1243-7 Lte\/us Simatic Cp 1243-7 Lte\/us Firmware Simatic Cp 1542sp-1 Simatic Cp 1542sp-1 Firmware Simatic Cp 1542sp-1 Irc Simatic Cp 1542sp-1 Irc Firmware Simatic Cp 1543sp-1 Simatic Cp 1543sp-1 Firmware Simatic Net Cp1243-7 Lte Eu Simatic Net Cp1243-7 Lte Eu Firmware Simatic Net Cp 1243-8 Irc Simatic Net Cp 1243-8 Irc Firmware Simatic Net Cp 1545-1 Simatic Net Cp 1545-1 Firmware Sinema Remote Connect Server Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware Siplus Et 200sp Cp 1543sp-1 Isec Siplus Et 200sp Cp 1543sp-1 Isec Firmware Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware Siplus Net Cp 1543-1 Siplus Net Cp 1543-1 Firmware Siplus S7-1200 Cp 1243-1 Siplus S7-1200 Cp 1243-1 Firmware Siplus S7-1200 Cp 1243-1 Rail Siplus S7-1200 Cp 1243-1 Rail Firmware
Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:22:25.655Z

Reserved: 2021-10-04T00:00:00.000Z

Link: CVE-2021-41991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-18T14:15:10.333

Modified: 2024-11-21T06:27:02.090

Link: CVE-2021-41991

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-10-18T00:00:00Z

Links: CVE-2021-41991 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses