Back

HIGH

strongswan: Insufficient Input Validation in gmp Plugin

Published Aug 18, 2017

Description

The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.

Affected products

Remediation

Red Hat statement

The version of strongimcv package shipped with Red Hat Enterprise Linux 7, does not enable the gmp plugin and therefore is not affected by this flaw.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 18, 2017
Updated Dec 4, 2025
Reserved Jul 12, 2017
CISA Vulnrichment
Updated Dec 4, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 14, 2017