Back

HIGH

strongswan: Insufficient validation of RSA public keys passed to the gmp plugin

Published Jun 8, 2017

Description

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of strongimcv as shipped with Red Hat Enterprise Linux 7, as they did not include support for the gmp plugin.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 8, 2017
Updated Dec 3, 2025
Reserved May 16, 2017
CISA Vulnrichment
Updated Dec 3, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 30, 2017