CVE-2017-9022 PUBLISHED

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

EPSS 1.03% · 77.2th percentile

Risk Scores

EPSS Score
1.03%
77.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSstrongswan0, 5.1.2-0ubuntu6, 5.1.2-0ubuntu7
Ubuntu:14.04:LTSstrongswan5.1.1-0ubuntu7, 5.1.1-0ubuntu14, 5.1.1-0ubuntu17

Timeline

References

Open in Interactive Console →