CVE-2023-41913: Buffer Overflow
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKESAINIT message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41913?
CVE-2023-41913 is a high severity vulnerability that can lead to buffer overflow and potential unauthenticated remote code execution.
How do I fix CVE-2023-41913?
To fix CVE-2023-41913, upgrade strongSwan to version 5.9.12 or later.
Which versions of strongSwan are affected by CVE-2023-41913?
strongSwan versions from 5.3.0 up to and including 5.9.11 are affected by CVE-2023-41913.
Can CVE-2023-41913 be exploited remotely?
Yes, CVE-2023-41913 can be exploited remotely through a crafted IKE_SA_INIT message.
What is the impact of CVE-2023-41913?
The impact of CVE-2023-41913 includes possible remote code execution and compromise of the affected system.