Vulnerabilities (CVE)

Filtered by vendor Strongswan Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-6459 1 Strongswan 1 Strongswan 2020-03-30 5.0 MEDIUM 5.3 MEDIUM
The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter.
CVE-2018-5388 3 Canonical, Debian, Strongswan 3 Ubuntu Linux, Debian Linux, Strongswan 2019-10-09 4.0 MEDIUM 6.5 MEDIUM
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.