Описание
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 5.1.2-0ubuntu1 |
| esm-infra-legacy/trusty | not-affected | 5.1.2-0ubuntu1 |
| esm-infra/xenial | not-affected | 5.1.2-0ubuntu1 |
| hardy | ignored | end of life |
| lucid | ignored | end of life |
| oneiric | ignored | end of life |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needed |
| quantal | ignored | end of life |
| raring | ignored | end of life |
Показывать по
Ссылки на источники
EPSS
4.9 Medium
CVSS2
Связанные уязвимости
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDS ...
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
4.9 Medium
CVSS2