USN-6488-2: strongSwan vulnerability
USN-6488-1 fixed a vulnerability in strongSwan. This update provides the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: Florian Picca discovered that strongSwan incorrectly handled certain DH public values. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6488-2?
USN-6488-2 addresses a critical vulnerability that could allow a remote attacker to exploit incorrect handling of DH public values.
How do I fix USN-6488-2?
To fix USN-6488-2, upgrade the strongSwan and libstrongswan packages to the versions specified in the advisory.
Which Ubuntu versions are affected by USN-6488-2?
USN-6488-2 affects Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Who discovered the vulnerability related to USN-6488-2?
The vulnerability addressed in USN-6488-2 was discovered by Florian Picca.
What is the impact of not addressing USN-6488-2?
Failure to address USN-6488-2 may leave your system vulnerable to remote attacks that exploit the identified weakness.