ZeroHour

CVE-2017-9022

CVSS 3.1
7.5 high
EPSS
2%p76
Published
()
Modified
Description

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

Vendors
strongswandebiancanonical
Products
strongswan, debian linux, ubuntu linux
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.