Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
strongSwan could be made to bypass authentication.
Software Description:
- strongswan: IPsec VPN solution
Details:
It was discovered that the strongSwan eap-mschapv2 plugin incorrectly
handled state. A remote attacker could use this issue to bypass
authentication.
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: strongswan-plugin-eap-mschapv2 5.1.2-0ubuntu6.2 Ubuntu 15.04: strongswan-plugin-eap-mschapv2 5.1.2-0ubuntu5.3 Ubuntu 14.04 LTS: strongswan-plugin-eap-mschapv2 5.1.2-0ubuntu2.4 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2811-1
CVE-2015-8023
Get the latest Linux and open source security news straight to your inbox.