First published: Wed Nov 18 2015(Updated: )
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =15.04 | |
Canonical Ubuntu Linux | =15.10 | |
Strongswan Strongswan | =4.2.12 | |
Strongswan Strongswan | =4.2.13 | |
Strongswan Strongswan | =4.2.14 | |
Strongswan Strongswan | =4.2.15 | |
Strongswan Strongswan | =4.2.16 | |
Strongswan Strongswan | =4.3.0 | |
Strongswan Strongswan | =4.3.1 | |
Strongswan Strongswan | =4.3.2 | |
Strongswan Strongswan | =4.3.3 | |
Strongswan Strongswan | =4.3.4 | |
Strongswan Strongswan | =4.3.5 | |
Strongswan Strongswan | =4.3.6 | |
Strongswan Strongswan | =4.3.7 | |
Strongswan Strongswan | =4.4.0 | |
Strongswan Strongswan | =4.4.1 | |
Strongswan Strongswan | =4.5.0 | |
Strongswan Strongswan | =4.5.1 | |
Strongswan Strongswan | =4.5.2 | |
Strongswan Strongswan | =4.5.3 | |
Strongswan Strongswan | =4.6.0 | |
Strongswan Strongswan | =4.6.1 | |
Strongswan Strongswan | =4.6.2 | |
Strongswan Strongswan | =4.6.3 | |
Strongswan Strongswan | =4.6.4 | |
Strongswan Strongswan | =5.0.0 | |
Strongswan Strongswan | =5.0.1 | |
Strongswan Strongswan | =5.0.2 | |
Strongswan Strongswan | =5.0.3 | |
Strongswan Strongswan | =5.0.4 | |
Strongswan Strongswan | =5.1.0 | |
Strongswan Strongswan | =5.1.1 | |
Strongswan Strongswan | =5.1.2 | |
Strongswan Strongswan | =5.1.3 | |
Strongswan Strongswan | =5.2.0 | |
Strongswan Strongswan | =5.2.1 | |
Strongswan Strongswan | =5.2.2 | |
Strongswan Strongswan | =5.2.3 | |
Strongswan Strongswan | =5.3.0 | |
Strongswan Strongswan | =5.3.1 | |
Strongswan Strongswan | =5.3.2 | |
Strongswan Strongswan | =5.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.