Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7mg-4vgp-5j3h

Опубликовано: 07 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

EPSS

Процентиль: 93%
0.1093
Средний

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

CVSS3: 9.8
nvd
больше 1 года назад

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
больше 1 года назад

strongSwan before 5.9.12 has a buffer overflow and possible unauthenti ...

suse-cvrf
больше 1 года назад

Security update for strongswan

EPSS

Процентиль: 93%
0.1093
Средний

9.8 Critical

CVSS3

Дефекты

CWE-120