PublicDateAtUSN: 2017-08-18 Candidate: CVE-2017-11185 PublicDate: 2017-08-18 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11185 https://www.strongswan.org/blog/2017/08/14/strongswan-vulnerability-(cve-2017-11185).html https://ubuntu.com/security/notices/USN-3397-1 Description: The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature. Ubuntu-Description: Notes: sdeziel> Remote code execution is not possible. Bugs: Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_strongswan: upstream: https://wiki.strongswan.org/projects/strongswan/repository/revisions/ef5c37fcdf47273feea320091598135688df4ef7 upstream: https://download.strongswan.org/security/CVE-2017-11185/strongswan-4.4.0-5.5.3_gmp_mpz_export.patch upstream_strongswan: released (5.6.0) precise/esm_strongswan: DNE trusty_strongswan: released (5.1.2-0ubuntu2.7) trusty/esm_strongswan: released (5.1.2-0ubuntu2.7) vivid/ubuntu-core_strongswan: DNE xenial_strongswan: released (5.3.5-1ubuntu3.4) esm-infra/xenial_strongswan: released (5.3.5-1ubuntu3.4) zesty_strongswan: released (5.5.1-1ubuntu3.2) devel_strongswan: released (5.5.1-4ubuntu2)