CVE-2017-11185: Null Pointer Dereference
Published Aug 18, 2017
·Updated
The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.
Affected Software
1 affected component
strongSwan Strongswan<=5.5.3
Event History
Aug 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-11185?
CVE-2017-11185 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2017-11185?
To mitigate CVE-2017-11185, upgrade strongSwan to version 5.6.0 or later.
3
What kind of attack does CVE-2017-11185 involve?
CVE-2017-11185 allows remote attackers to trigger a denial of service through a crafted RSA signature.
4
Which versions of strongSwan are affected by CVE-2017-11185?
CVE-2017-11185 affects strongSwan versions prior to 5.6.0, specifically up to and including 5.5.3.
5
Is CVE-2017-11185 a local or remote vulnerability?
CVE-2017-11185 is a remote vulnerability that can be exploited by attackers without physical access.