• [SECURITY] [DSA 3962-1] strongswan security update

    From Yves-Alexis Perez@1:229/2 to All on Sun Sep 3 15:30:01 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3962-1 [email protected] https://www.debian.org/security/ Yves-Alexis Perez September 03, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : strongswan
    CVE ID : CVE-2017-11185
    Debian Bug : 872155

    A denial of service vulnerability was identified in strongSwan, an IKE/IPsec suite, using Google's OSS-Fuzz fuzzing project.

    The gmp plugin in strongSwan had insufficient input validation when verifying RSA signatures. This coding error could lead to a null pointer dereference, leading to process crash.

    For the oldstable distribution (jessie), this problem has been fixed
    in version 5.2.1-6+deb8u5.

    For the stable distribution (stretch), this problem has been fixed in
    version 5.5.1-4+deb9u1.

    For the testing distribution (buster), this problem has been fixed
    in version 5.6.0-1.

    For the unstable distribution (sid), this problem has been fixed in
    version 5.6.0-1.

    We recommend that you upgrade your strongswan packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEl0WwInMjgf6efq/1bdtT8qZ1wKUFAlmr/jQACgkQbdtT8qZ1 wKVE7Qf8Coj8LA6YWjPOyOxCrevipzaH9Az/BXLHF6lNkN+oyfaGjcSpSwha5Uw0 ItGWc4aIlQjiICZp8LMPEcQSajZwgJN6EvumQb/sxR88laQLUP28sEr+ADziE0Bl qsitCUf8J0YVhZ+xOEu+HF15MI/oDsbYNlMhyw1ZBimcMqsAMpDC7nvsIzf5l2Xp qiF+VVs+TxVQto4GHlQGm9V5DCDXA2QujnzGsOcdutgeHG0p6Eb9mnXN5TF0UqfO WTILsRFesEy3RZsUvzboqjtD/gn0NVJlxI6k/eFjrxSaLYVXDvgOWLlX+yK6hiOu +x/JYiOkOsKfRfRHi5ZnBI2WXMN5OA==
    =rYat
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)