USN-6488-1: strongSwan vulnerability
Florian Picca discovered that strongSwan incorrectly handled certain DH public values. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6488-1?
The severity of USN-6488-1 is significant due to the potential for denial of service and arbitrary code execution.
How do I fix USN-6488-1?
To fix USN-6488-1, update strongSwan and libstrongswan to the versions 5.9.11-1ubuntu1.1 or higher on your Ubuntu system.
Which versions of strongSwan are affected by USN-6488-1?
USN-6488-1 affects strongSwan versions up to 5.9.11-1ubuntu1.1 for Ubuntu 23.10, 23.04, and 22.04.
Which versions of libstrongswan are affected by USN-6488-1?
USN-6488-1 affects libstrongswan versions up to 5.9.11-1ubuntu1.1 for Ubuntu 23.10, 23.04, and 22.04.
Is there a known exploit for USN-6488-1?
Yes, USN-6488-1 can be exploited by a remote attacker to crash strongSwan or potentially execute arbitrary code.