CVE-2018-5388: Medium severity strongSwan Strongswan vulnerability
In strokesocket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/strongswanto a version that resolves this vulnerability.Fixed in 5.9.1-1+deb11u4Fixed in 5.9.1-1+deb11u5Fixed in 5.9.8-5+deb12u2Fixed in 6.0.1-6+deb13u2Fixed in 6.0.4-1 - Upgrade
Upgrade
strongSwanto a version that resolves this vulnerability.Fixed in 5.6.3
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-5388.
What is the severity of CVE-2018-5388?
The severity of CVE-2018-5388 is medium (6.5).
How does CVE-2018-5388 affect strongSwan?
CVE-2018-5388 in strongSwan before 5.6.3 could lead to resource exhaustion and denial of service.
Which software versions are affected by CVE-2018-5388?
strongSwan versions 5.6.2-1ubuntu2.2, 5.1.2-0ubuntu2.10, 5.6.3, 5.3.5-1ubuntu3.7, 5.7.2-1+deb10u2, 5.7.2-1+deb10u3, 5.9.1-1+deb11u3, 5.9.8-5, 5.9.11-1 are affected.
How can I fix CVE-2018-5388?
To fix CVE-2018-5388, you should update strongSwan to version 5.6.3 or apply the provided remedies for your specific version.