CVE-2018-16151: High severity strongSwan Strongswan vulnerability
In verifyemsapkcs1signature() in gmprsapublickey.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification. Similar to the flaw in the same version of strongSwan regarding digestAlgorithm.parameters, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-16151?
CVE-2018-16151 is a vulnerability in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0 that allows for excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification.
How severe is CVE-2018-16151?
CVE-2018-16151 has a severity level of 7.5 (High).
Which versions of strongSwan are affected by CVE-2018-16151?
strongSwan versions 4.x and 5.x before 5.7.0 are affected by CVE-2018-16151.
How can I fix CVE-2018-16151?
To fix CVE-2018-16151, update to strongSwan version 5.7.0 or later.
Where can I find more information about CVE-2018-16151?
You can find more information about CVE-2018-16151 at the following references: [1] [2] [3].