This update for strongswan fixes the following issues:
Strongswan was updated to version 5.8.2 (jsc#SLE-11370).
Security issue fixed:
- CVE-2018-6459: Fixed a DoS vulnerability in the parser for PKCS#1
RSASSA-PSS signatures that was caused by insufficient input validation
(bsc#1079548).
Full changelogs:
Version 5.8.2
* Identity-based CA constraints, which enforce that the certificate
chain of the remote peer contains a CA certificate with a specific
identity, are supported via vici/swanctl.conf. This is similar to the
existing CA constraints but doesn't require that the CA certificate is
locally installed, for instance, intermediate CA certificates received
from the peers. Wildcard identity matching (e.g. ..., OU=Research,
CN=*) could also be used for the latter but requires trust in the
intermediate CAs to only issue certificates with legitimate subject
DNs (e.g. the "Sales" CA must not...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-403=1
- openSUSE Leap 15.1 (noarch):
strongswan-doc-5.8.2-lp151.4.6.1
- openSUSE Leap 15.1 (x86_64):
strongswan-5.8.2-lp151.4.6.1
strongswan-debuginfo-5.8.2-lp151.4.6.1
strongswan-debugsource-5.8.2-lp151.4.6.1
strongswan-hmac-5.8.2-lp151.4.6.1
strongswan-ipsec-5.8.2-lp151.4.6.1
strongswan-ipsec-debuginfo-5.8.2-lp151.4.6.1
strongswan-libs0-5.8.2-lp151.4.6.1
strongswan-libs0-debuginfo-5.8.2-lp151.4.6.1
strongswan-mysql-5.8.2-lp151.4.6.1
strongswan-mysql-debuginfo-5.8.2-lp151.4.6.1
strongswan-nm-5.8.2-lp151.4.6.1
strongswan-nm-debuginfo-5.8.2-lp151.4.6.1
strongswan-sqlite-5.8.2-lp151.4.6.1
strongswan-sqlite-debuginfo-5.8.2-lp151.4.6.1
https://www.suse.com/security/cve/CVE-2018-6459.html
https://bugzilla.suse.com/1079548
--
Get the latest Linux and open source security news straight to your inbox.