CVE-2015-3991: Critical severity strongswan vulnerability
A flaw was found in the strongSwan payload handling code. This flaw can be triggered by an IKEv1 or IKEv2 message that contains payloads that are only defined for the respective other IKE version. For instance, sending an IKEv1 Main Mode message containing a payload with type 41 (IKEv2 Notify) will crash the daemon or, potentially allow for remote code execution, when a short summary of the contents of the message is logged ("parsed IDPROT request 0 [ ... ]").
Other sources
strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3991?
CVE-2015-3991 has been classified as a medium severity vulnerability due to its potential to disrupt secure communication protocols.
How do I fix CVE-2015-3991?
To mitigate CVE-2015-3991, upgrade strongSwan to version 5.3.1 or later.
What software versions are affected by CVE-2015-3991?
CVE-2015-3991 affects strongSwan versions 5.2.2, 5.3.0, and earlier.
What types of payloads can trigger CVE-2015-3991?
CVE-2015-3991 can be triggered by IKEv1 or IKEv2 messages containing inappropriate payload types from the other version.
Is CVE-2015-3991 a remote code execution vulnerability?
CVE-2015-3991 does not constitute a remote code execution vulnerability but can pose significant risks to communication integrity.