CVE-2018-5388 PUBLISHED

In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

EPSS 4.30% · 88.8th percentile

Risk Scores

EPSS Score
4.30%
88.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSstrongswan5.6.2-1ubuntu2, 5.6.1-2ubuntu4, 5.6.1-2ubuntu3
Ubuntu:14.04:LTSstrongswan5.1.1-0ubuntu5, 5.1.1-0ubuntu7, 5.1.1-0ubuntu14
Ubuntu:16.04:LTSstrongswan5.3.5-1ubuntu3.2, 5.3.5-1ubuntu3.3, 5.3.5-1ubuntu3.4

Timeline

References

Open in Interactive Console →