Hide Forgot
Because the revocation plugin uses potentially untrusted OCSP URIs and CRL distribution points (CDP) in certificates, a remote attacker is able to initiate IKE_SAs and send crafted certificates that contain URIs pointing to servers under their control, which can lead to a denial-of-service attack. Affected are all strongSwan versions if they use the revocation plugin or a custom plugin that implements similar features.
Created strongswan tracking bugs for this issue: Affects: epel-all [bug 2132445] Affects: fedora-all [bug 2132446]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.