Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:3855-1

Опубликовано: 29 окт. 2025
Источник: suse-cvrf

Описание

Security update for strongswan

This update for strongswan fixes the following issues:

  • CVE-2025-62291: fixed buffer overflow when handling EAP-MSCHAPv2 failure requests (bsc#1251941)

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP6
strongswan-5.9.12-150600.3.5.2
strongswan-doc-5.9.12-150600.3.5.2
strongswan-hmac-5.9.12-150600.3.5.2
strongswan-ipsec-5.9.12-150600.3.5.2
strongswan-libs0-5.9.12-150600.3.5.2
SUSE Linux Enterprise Module for Package Hub 15 SP6
strongswan-nm-5.9.12-150600.3.5.2
SUSE Linux Enterprise Workstation Extension 15 SP6
strongswan-nm-5.9.12-150600.3.5.2
openSUSE Leap 15.6
strongswan-5.9.12-150600.3.5.2
strongswan-doc-5.9.12-150600.3.5.2
strongswan-hmac-5.9.12-150600.3.5.2
strongswan-ipsec-5.9.12-150600.3.5.2
strongswan-libs0-5.9.12-150600.3.5.2
strongswan-mysql-5.9.12-150600.3.5.2
strongswan-nm-5.9.12-150600.3.5.2
strongswan-sqlite-5.9.12-150600.3.5.2

Описание

In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:strongswan-5.9.12-150600.3.5.2
SUSE Linux Enterprise Module for Basesystem 15 SP6:strongswan-doc-5.9.12-150600.3.5.2
SUSE Linux Enterprise Module for Basesystem 15 SP6:strongswan-hmac-5.9.12-150600.3.5.2
SUSE Linux Enterprise Module for Basesystem 15 SP6:strongswan-ipsec-5.9.12-150600.3.5.2

Ссылки
Уязвимость SUSE-SU-2025:3855-1