Количество 9
Количество 9
BDU:2024-07353
Уязвимость плагина revocation VPN-клиента StrongSwan, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data.
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of s ...
SUSE-SU-2022:4197-1
Security update for strongswan
SUSE-SU-2022:4185-1
Security update for strongswan
SUSE-SU-2022:4159-1
Security update for strongswan
GHSA-f2x8-4jwf-gqrg
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-07353 Уязвимость плагина revocation VPN-клиента StrongSwan, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of s ... | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
SUSE-SU-2022:4197-1 Security update for strongswan | 0% Низкий | около 3 лет назад | ||
SUSE-SU-2022:4185-1 Security update for strongswan | 0% Низкий | около 3 лет назад | ||
SUSE-SU-2022:4159-1 Security update for strongswan | 0% Низкий | около 3 лет назад | ||
GHSA-f2x8-4jwf-gqrg strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу