Описание
Security update for strongswan
This update for strongswan fixes the following issues:
- CVE-2025-62291: fixed buffer overflow when handling EAP-MSCHAPv2 failure requests (bsc#1251941)
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
strongswan-5.1.3-26.29.1
strongswan-doc-5.1.3-26.29.1
strongswan-hmac-5.1.3-26.29.1
strongswan-ipsec-5.1.3-26.29.1
strongswan-libs0-5.1.3-26.29.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
strongswan-5.1.3-26.29.1
strongswan-doc-5.1.3-26.29.1
strongswan-hmac-5.1.3-26.29.1
strongswan-ipsec-5.1.3-26.29.1
strongswan-libs0-5.1.3-26.29.1
Ссылки
- Link for SUSE-SU-2025:3904-1
- E-Mail link for SUSE-SU-2025:3904-1
- SUSE Security Ratings
- SUSE Bug 1251941
- SUSE CVE CVE-2025-62291 page
Описание
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:strongswan-5.1.3-26.29.1
SUSE Linux Enterprise Server 12 SP5-LTSS:strongswan-doc-5.1.3-26.29.1
SUSE Linux Enterprise Server 12 SP5-LTSS:strongswan-hmac-5.1.3-26.29.1
SUSE Linux Enterprise Server 12 SP5-LTSS:strongswan-ipsec-5.1.3-26.29.1
Ссылки
- CVE-2025-62291
- SUSE Bug 1251941