Back

HIGH

strongswan: gmp plugin: integer overflow via a crafted certificate with an RSASSA-PSS signature

Published Oct 18, 2021

Description

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

Affected products

Remediation

No remediation recorded yet.

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Oct 18, 2021
Updated Aug 4, 2024
Reserved Oct 4, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 18, 2021
Bugzilla 2015610

ENISA EUVD

Assigner mitre
Published Oct 18, 2021
Updated Aug 4, 2024

GitHub

No data