Vulnerabilities > CVE-2017-11185 - NULL Pointer Dereference vulnerability in Strongswan
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Debian Local Security Checks NASL id DEBIAN_DLA-1059.NASL description It was discovered that there was a denial of service vulnerability in the Strongswan Virtual Private Network (VPN) software. Specific RSA signatures passed to the gmp plugin for verification could cause a NULL pointer dereference. Potential triggers are signatures in certificates, but also signatures used during IKE authentication. For more details, please see : <https://www.strongswan.org/blog/2017/08/14/strongswan-vulnerability-( cve-2017-11185).html> For Debian 7 last seen 2020-03-17 modified 2017-08-21 plugin id 102594 published 2017-08-21 reporter This script is Copyright (C) 2017-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/102594 title Debian DLA-1059-1 : strongswan security update NASL family Ubuntu Local Security Checks NASL id UBUNTU_USN-3397-1.NASL description It was discovered that strongSwan incorrectly handled verifying specific RSA signatures. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 102678 published 2017-08-22 reporter Ubuntu Security Notice (C) 2017-2019 Canonical, Inc. / NASL script (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/102678 title Ubuntu 14.04 LTS / 16.04 LTS / 17.04 : strongswan vulnerability (USN-3397-1) NASL family PhotonOS Local Security Checks NASL id PHOTONOS_PHSA-2017-0040.NASL description An update of [openjdk,openjre,bash,libtar,glibc,libgcrypt,strongswan,unzip] packages for PhotonOS has been released. last seen 2019-02-21 modified 2019-02-07 plugin id 111889 published 2018-08-17 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=111889 title Photon OS 1.0: Bash / Glibc / Libgcrypt / Libtar / Openjdk / Openjre / Strongswan / Unzip PHSA-2017-0040 (deprecated) NASL family SuSE Local Security Checks NASL id SUSE_SU-2017-2293-1.NASL description This update for strongswan fixes the following issues : - CVE-2017-11185: Specific RSA signatures passed to the gmp plugin for verification can cause a NULL pointer dereference and it may lead to a denial of service (bsc#1051222) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 102840 published 2017-08-30 reporter This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/102840 title SUSE SLES11 Security Update : strongswan (SUSE-SU-2017:2293-1) NASL family SuSE Local Security Checks NASL id SUSE_SU-2017-2143-1.NASL description This update for strongswan fixes the following issues : - CVE-2017-11185: Specific RSA signatures passed to the gmp plugin for verification can cause a NULL pointer dereference and it may lead to a denial of service (bsc#1051222) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 102476 published 2017-08-14 reporter This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/102476 title SUSE SLED12 / SLES12 Security Update : strongswan (SUSE-SU-2017:2143-1) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-3962.NASL description A denial of service vulnerability was identified in strongSwan, an IKE/IPsec suite, using Google last seen 2020-06-01 modified 2020-06-02 plugin id 102929 published 2017-09-05 reporter This script is Copyright (C) 2017-2018 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/102929 title Debian DSA-3962-1 : strongswan - security update NASL family PhotonOS Local Security Checks NASL id PHOTONOS_PHSA-2017-0040_STRONGSWAN.NASL description An update of the strongswan package has been released. last seen 2020-03-17 modified 2019-02-07 plugin id 121747 published 2019-02-07 reporter This script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/121747 title Photon OS 1.0: Strongswan PHSA-2017-0040