Beveiligingsadvies

CVE-2017-9022

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-06-08 16:00:00
Laatst bijgewerkt 2025-12-03 21:16:39
Toegewezen door mitre
CVSS-score 7.5
Status PUBLISHED

Beschrijving

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.