Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:3834-1

Опубликовано: 28 окт. 2025
Источник: suse-cvrf

Описание

Security update for strongswan

This update for strongswan fixes the following issues:

  • CVE-2025-62291: fixed buffer overflow when handling EAP-MSCHAPv2 failure requests (bsc#1251941)

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP7
strongswan-5.9.14-150700.3.3.1
strongswan-doc-5.9.14-150700.3.3.1
strongswan-hmac-5.9.14-150700.3.3.1
strongswan-ipsec-5.9.14-150700.3.3.1
strongswan-libs0-5.9.14-150700.3.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
strongswan-nm-5.9.14-150700.3.3.1
SUSE Linux Enterprise Workstation Extension 15 SP7
strongswan-nm-5.9.14-150700.3.3.1

Описание

In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:strongswan-5.9.14-150700.3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:strongswan-doc-5.9.14-150700.3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:strongswan-hmac-5.9.14-150700.3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:strongswan-ipsec-5.9.14-150700.3.3.1

Ссылки