CVE-2017-9023: High severity strongswan vulnerability
Published Jun 8, 2017
·Updated
The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.
Affected Software
1 affected component
strongSwan Strongswan<=5.5.2
Event History
Jun 8, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-9023?
CVE-2017-9023 is classified as a denial of service vulnerability due to the infinite loop caused by crafted certificates.
2
How do I fix CVE-2017-9023?
To fix CVE-2017-9023, upgrade strongSwan to version 5.5.3 or later.
3
Which versions of strongSwan are affected by CVE-2017-9023?
strongSwan versions prior to 5.5.3, specifically up to 5.5.2, are affected by CVE-2017-9023.
4
What component of strongSwan is impacted by CVE-2017-9023?
The ASN.1 parser in strongSwan is impacted by CVE-2017-9023 when the x509 plugin is enabled.
5
Can CVE-2017-9023 be exploited remotely?
Yes, CVE-2017-9023 can be exploited remotely by attackers using specially crafted certificates.