USN-6772-1: strongSwan vulnerability
Published May 14, 2024
·Updated
Jan Schermer discovered that strongSwan incorrectly validated client certificates in certain configurations. A remote attacker could possibly use this issue to bypass access controls.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/libstrongswan<5.9.5-2ubuntu2.3
5.9.5-2ubuntu2.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/strongswan<5.9.5-2ubuntu2.3
5.9.5-2ubuntu2.3
Ubuntu Ubuntu=22.04
Event History
May 14, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6772-1?
The severity of USN-6772-1 is categorized as high due to the potential for a remote attacker to bypass access controls.
2
How do I fix USN-6772-1?
To fix USN-6772-1, you should upgrade the libstrongswan and strongswan packages to version 5.9.5-2ubuntu2.3 or later.
3
Which versions of strongSwan are affected by USN-6772-1?
Versions of strongSwan prior to 5.9.5-2ubuntu2.3 in Ubuntu 22.04 are affected by USN-6772-1.
4
Can USN-6772-1 be exploited remotely?
Yes, USN-6772-1 can be exploited remotely if certain configurations are in place, allowing attackers to bypass access controls.
5
Who discovered the vulnerability in USN-6772-1?
The vulnerability in USN-6772-1 was discovered by Jan Schermer.