Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-40617

Опубликовано: 31 окт. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.

РелизСтатусПримечание
bionic

released

5.6.2-1ubuntu2.9
devel

released

5.9.6-1ubuntu2
esm-infra-legacy/trusty

released

5.1.2-0ubuntu2.11+esm3
esm-infra-legacy/xenial

released

5.3.5-1ubuntu3.8+esm3
esm-infra/bionic

released

5.6.2-1ubuntu2.9
esm-infra/focal

released

5.8.2-1ubuntu3.5
esm-infra/xenial

released

5.3.5-1ubuntu3.8+esm3
fips-preview/jammy

released

5.9.5-2ubuntu2.1
fips-updates/bionic

released

5.6.2-1ubuntu2.fips.2.9
fips-updates/focal

released

5.8.2-1ubuntu3.fips.3.5

Показывать по

EPSS

Процентиль: 74%
0.01634
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.

CVSS3: 7.5
msrc
почти 4 года назад

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data.

CVSS3: 7.5
debian
почти 4 года назад

strongSwan before 5.9.8 allows remote attackers to cause a denial of s ...

suse-cvrf
больше 3 лет назад

Security update for strongswan

suse-cvrf
больше 3 лет назад

Security update for strongswan

EPSS

Процентиль: 74%
0.01634
Низкий

7.5 High

CVSS3