Red Hat Bugzilla – Bug 1635877
CVE-2018-17540 strongswan: heap buffer overflow using crafted certificates
Last modified: 2018-10-03 16:10:43 EDT
A flaw was found in Strongswan caused by the patch that fixes CVE-2018-16151 and CVE-2018-16151 (DSA-4305-1). An attacker could trigger it using crafted certificates with RSA keys with very small moduli. Verifying signatures with such keys would cause an integer underflow and subsequent heap buffer overflow resulting in a crash of the daemon. References: https://packetstormsecurity.com/files/149640/dsa-4309-1.txt
Created strongswan tracking bugs for this issue: Affects: epel-all [bug 1635878] Affects: fedora-all [bug 1635879]