Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9023

Опубликовано: 08 июн. 2017
Источник: debian
EPSS Низкий

Описание

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
strongswanfixed5.5.1-4package

Примечания

  • upstream fix https://git.strongswan.org/?p=strongswan.git;a=commit;h=407fcca200fdf6a41a04ac0885a770b6b53c5d23

EPSS

Процентиль: 84%
0.02101
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

CVSS3: 3.7
redhat
больше 8 лет назад

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

CVSS3: 7.5
nvd
больше 8 лет назад

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

CVSS3: 7.5
github
больше 3 лет назад

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

suse-cvrf
больше 8 лет назад

Security update for strongswan

EPSS

Процентиль: 84%
0.02101
Низкий