Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

openSUSE: 2020:0403-1 Moderate: strongswan DoS Issue Resolved

opensuse
Calendar Grey March 29, 2020
Dist Opensuse Esm H88
This Ubuntu announcement highlights a critical security patch for OpenSSH targeting a potential attack vector.
An update that fixes one vulnerability is now available.

Description

This update for strongswan fixes the following issues:

Strongswan was updated to version 5.8.2 (jsc#SLE-11370).

Security issue fixed:

- CVE-2018-6459: Fixed a DoS vulnerability in the parser for PKCS#1

RSASSA-PSS signatures that was caused by insufficient input validation

(bsc#1079548).

Full changelogs:

Version 5.8.2

* Identity-based CA constraints, which enforce that the certificate

chain of the remote peer contains a CA certificate with a specific

identity, are supported via vici/swanctl.conf. This is similar to the

existing CA constraints but doesn't require that the CA certificate is

locally installed, for instance, intermediate CA certificates received

from the peers. Wildcard identity matching (e.g. ..., OU=Research,

CN=*) could also be used for the latter but requires trust in the

intermediate CAs to only issue certificates with legitimate subject

DNs (e.g. the "Sales" CA must not...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-403=1

Package List

- openSUSE Leap 15.1 (noarch):

strongswan-doc-5.8.2-lp151.4.6.1

- openSUSE Leap 15.1 (x86_64):

strongswan-5.8.2-lp151.4.6.1

strongswan-debuginfo-5.8.2-lp151.4.6.1

strongswan-debugsource-5.8.2-lp151.4.6.1

strongswan-hmac-5.8.2-lp151.4.6.1

strongswan-ipsec-5.8.2-lp151.4.6.1

strongswan-ipsec-debuginfo-5.8.2-lp151.4.6.1

strongswan-libs0-5.8.2-lp151.4.6.1

strongswan-libs0-debuginfo-5.8.2-lp151.4.6.1

strongswan-mysql-5.8.2-lp151.4.6.1

strongswan-mysql-debuginfo-5.8.2-lp151.4.6.1

strongswan-nm-5.8.2-lp151.4.6.1

strongswan-nm-debuginfo-5.8.2-lp151.4.6.1

strongswan-sqlite-5.8.2-lp151.4.6.1

strongswan-sqlite-debuginfo-5.8.2-lp151.4.6.1

References

https://www.suse.com/security/cve/CVE-2018-6459.html

https://bugzilla.suse.com/1079548

--

Announcement ID: openSUSE-SU-2020:0403-1
Rating: moderate
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here