Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-41990
HistoryOct 18, 2021 - 12:00 a.m.

CVE-2021-41990

2021-10-1800:00:00
ubuntu.com
ubuntu.com
20
strongswan
gmp plugin
remote integer overflow
crafted certificate
rsassa-pss signature
self-signed ca certificate
initiator
remote code execution
unix

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.04

Percentile

92.1%

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via
a crafted certificate with an RSASSA-PSS signature. For example, this can
be triggered by an unrelated self-signed CA certificate sent by an
initiator. Remote code execution cannot occur.

Notes

Author Note
mdeslaur affects 5.6.1+
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchstrongswan< 5.6.2-1ubuntu2.7UNKNOWN
ubuntu20.04noarchstrongswan< 5.8.2-1ubuntu3.3UNKNOWN
ubuntu21.04noarchstrongswan< 5.9.1-1ubuntu1.2UNKNOWN
ubuntu21.10noarchstrongswan< 5.9.1-1ubuntu3.1UNKNOWN
ubuntu22.04noarchstrongswan< 5.9.1-1ubuntu3.1UNKNOWN
ubuntu22.10noarchstrongswan< 5.9.1-1ubuntu3.1UNKNOWN
ubuntu23.04noarchstrongswan< 5.9.1-1ubuntu3.1UNKNOWN
ubuntu23.10noarchstrongswan< 5.9.1-1ubuntu3.1UNKNOWN
ubuntu24.04noarchstrongswan< 5.9.1-1ubuntu3.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.04

Percentile

92.1%