Back

MEDIUM

strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c

Published May 31, 2018

Description

In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

Affected products

Remediation

Red Hat mitigation

On Red Hat Enterprise Linux 7 only root has access to /var/run/charon.ctl so you need to be already root to exploit the vulnerability.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published May 31, 2018
Updated Aug 5, 2024
Reserved Jan 12, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 22, 2018