CVE-2018-6459: Medium severity strongSwan Strongswan vulnerability
The rsapssparamsparse function in libstrongswan/credentials/keys/signatureparams.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
<CVE-2018-6459>
What is the severity of <CVE-2018-6459>?
The severity of <CVE-2018-6459> is medium with a severity value of 5.3.
Which software version is affected by <CVE-2018-6459>?
The version affected by <CVE-2018-6459> is Strongswan 5.6.1.
How can an attacker exploit <CVE-2018-6459>?
An attacker can exploit <CVE-2018-6459> by sending a crafted RSASSA-PSS signature that lacks a mask generation function parameter, causing a denial of service.
Are there any references available for <CVE-2018-6459>?
Yes, the references for <CVE-2018-6459> are: [1] http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00047.html, [2] https://security.gentoo.org/glsa/201811-16, [3] https://www.strongswan.org/blog/2018/02/19/strongswan-vulnerability-(cve-2018-6459).html