SB2018053023 - Buffer underflow in strongswan (Alpine package)
Published: May 30, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer underflow (CVE-ID: CVE-2018-5388)
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to buffer underflow stroke_socket.c while improper checking of packet length. A local attacker can submit specially crafted packets, trigger resource exhaustion and cause the service to crash while reading from the socket.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=142cd0660c759d91ccdd0b6b6fd5f4959413ed93
- https://git.alpinelinux.org/aports/commit/?id=69cb3c4ebb573f4427b512a8f3ce9f8da6edc356
- https://git.alpinelinux.org/aports/commit/?id=b2909ae5d93989f6f7aa2506a963bb8061269792
- https://git.alpinelinux.org/aports/commit/?id=f48354faeaa48613ec150ba912a378e92d8fd969