CVE-2018-17540: Buffer Overflow
Published Oct 3, 2018
·Updated
Last updated 25 August 2025
Other sources
The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.
— Launchpad
Affected Software
7 affected componentsFixes available
strongSwan Strongswan<5.7.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
debian/strongswan
5.9.1-1+deb11u45.9.1-1+deb11u55.9.8-5+deb12u26.0.1-6+deb13u26.0.4-1
Remediation
Patch Available
Event History
Oct 3, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:54 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:55 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:56 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-17540?
CVE-2018-17540 is a vulnerability in the gmp plugin in strongSwan before 5.7.1, which allows for a buffer overflow via a crafted certificate.
2
How severe is CVE-2018-17540?
CVE-2018-17540 has a severity of 7.5 (high).
3
Which software is affected by CVE-2018-17540?
Strongswan versions before 5.7.2-1+deb10u2, 5.7.2-1+deb10u3, 5.9.1-1+deb11u3, 5.9.8-5, and 5.9.11-1 on Debian Linux and Ubuntu Linux 14.04, 16.04, and 18.04 are affected.
4
How do I fix CVE-2018-17540?
To fix CVE-2018-17540, update your strongSwan package to version 5.7.2-1+deb10u2, 5.7.2-1+deb10u3, 5.9.1-1+deb11u3, 5.9.8-5, or 5.9.11-1.
5
Where can I find more information about CVE-2018-17540?
You can find more information about CVE-2018-17540 at the following references: [1] [2] [3].