First published: Fri Aug 18 2017(Updated: )
The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
strongSwan | <=5.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11185 has a medium severity rating due to its potential to cause denial of service.
To mitigate CVE-2017-11185, upgrade strongSwan to version 5.6.0 or later.
CVE-2017-11185 allows remote attackers to trigger a denial of service through a crafted RSA signature.
CVE-2017-11185 affects strongSwan versions prior to 5.6.0, specifically up to and including 5.5.3.
CVE-2017-11185 is a remote vulnerability that can be exploited by attackers without physical access.