HomeFreeBSD

security/vuxml: Record strongswan buffer overflow

Description

security/vuxml: Record strongswan buffer overflow

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated
remote code execution via a DH public value that exceeds the internal buffer in
charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can
occur via a crafted IKE_SA_INIT message.

NVD score not yet provided.

PR: 275620

Details

Provenance
fernapeAuthored on Dec 9 2023, 12:31 PM
Parents
R11:da4620c265d5: www/squid: update to 6.6
Branches
Unknown
Tags
Unknown