Количество 9
Количество 9
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data.
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of s ...
SUSE-SU-2022:4197-1
Security update for strongswan
SUSE-SU-2022:4185-1
Security update for strongswan
SUSE-SU-2022:4159-1
Security update for strongswan
GHSA-f2x8-4jwf-gqrg
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
BDU:2024-07353
Уязвимость плагина revocation VPN-клиента StrongSwan, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of s ... | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
SUSE-SU-2022:4197-1 Security update for strongswan | 0% Низкий | около 3 лет назад | ||
SUSE-SU-2022:4185-1 Security update for strongswan | 0% Низкий | около 3 лет назад | ||
SUSE-SU-2022:4159-1 Security update for strongswan | 0% Низкий | около 3 лет назад | ||
GHSA-f2x8-4jwf-gqrg strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
BDU:2024-07353 Уязвимость плагина revocation VPN-клиента StrongSwan, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу