Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
strongSwan 加密问题漏洞
Vulnerability Description
strongSwan 2.8.11之前的2.8,4.2.17之前的4.2,4.3.3之前的4.3版本中的asn1_length函数,并没有合适的处理带有特制的相对标识名(RDNs)的授权凭证, 这使得远程攻击者可以借助畸形的ASN.1数据,引起拒绝服务攻击(pluto IKE后台控制程序崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A