CVE-2017-9022: Input Validation
Published Jun 8, 2017
·Updated
The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpzpowmsec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
Affected Software
7 affected components
strongSwan Strongswan<=5.5.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=16.10
Canonical Ubuntu Linux=17.04
Remediation
Event History
Jun 8, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-9022?
CVE-2017-9022 has a severity level that may lead to denial of service due to improper validation of RSA public keys.
2
How do I fix CVE-2017-9022?
To fix CVE-2017-9022, upgrade strongSwan to version 5.5.3 or later.
3
Which versions of strongSwan are affected by CVE-2017-9022?
Versions of strongSwan prior to 5.5.3 are affected by CVE-2017-9022.
4
What type of attack does CVE-2017-9022 allow?
CVE-2017-9022 allows remote peers to cause a denial of service through crafted certificates.
5
Is CVE-2017-9022 relevant to Debian and Ubuntu systems?
Yes, CVE-2017-9022 affects certain versions of Debian and Ubuntu systems running vulnerable versions of strongSwan.