Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
strongSwan 安全漏洞
Vulnerability Description
strongSwan是瑞士Andreas Steffen个人开发者的一套Linux平台使用的开源的基于IPsec的VPN解决方案。该方案包含X.509公开密钥证书、安全储存私钥、智能卡等认证机制。 strongSwan 5.3.0及之后版本存在安全漏洞,该漏洞源于存在缓冲区溢出漏洞。攻击者可利用该漏洞执行远程代码。
CVSS Information
N/A
Vulnerability Type
N/A