CVE-2022-40617
Summary
| CVE | CVE-2022-40617 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-31 06:15:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: strongswan-5.9.8-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| strongSwan - strongSwan Vulnerability (CVE-2022-40617) |
|
www.strongswan.org |
|
| strongSwan - strongSwan Vulnerability (CVE-2022-40617) |
CONFIRM |
www.strongswan.org |
|
| [SECURITY] Fedora 37 Update: strongswan-5.9.8-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181113 Debian Security Update for strongswan (DSA 5249-1)
- 181129 Debian Security Update for strongswan (DLA 3143-1)
- 182709 Debian Security Update for strongswan (CVE-2022-40617)
- 198969 Ubuntu Security Notification for strongSwan Vulnerability (USN-5651-1)
- 283243 Fedora Security Update for strongswan (FEDORA-2022-11bf2b2597)
- 283471 Fedora Security Update for strongswan (FEDORA-2022-525510c815)
- 502520 Alpine Linux Security Update for strongswan
- 502521 Alpine Linux Security Update for strongswan
- 502522 Alpine Linux Security Update for strongswan
- 502523 Alpine Linux Security Update for strongswan
- 502791 Alpine Linux Security Update for strongswan
- 690957 Free Berkeley Software Distribution (FreeBSD) Security Update for strongswan (0ae56f3e-488c-11ed-bb31-b42e99a1b9c3)
- 752821 SUSE Enterprise Linux Security Update for strongswan (SUSE-SU-2022:4159-1)
- 752838 SUSE Enterprise Linux Security Update for strongswan (SUSE-SU-2022:4197-1)
- 752873 SUSE Enterprise Linux Security Update for strongswan (SUSE-SU-2022:4185-1)
- 904442 Common Base Linux Mariner (CBL-Mariner) Security Update for strongswan (11422)
- 904480 Common Base Linux Mariner (CBL-Mariner) Security Update for strongswan (11398)
- 904781 Common Base Linux Mariner (CBL-Mariner) Security Update for strongswan (11398-1)
- 905667 Common Base Linux Mariner (CBL-Mariner) Security Update for strongswan (11422-1)
- 906563 Common Base Linux Mariner (CBL-Mariner) Security Update for strongswan (11422-3)