QID 198644

Date Published: 2022-01-25

QID 198644: Ubuntu Security Notification for strongSwan Vulnerability (USN-5250-1)

Stringswan incorrectly handled eapauthentication.

A remote attacker could use this issue to cause strongswanto crash, resulting in a denial of service, or possibly bypass client andserver authentication.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5250-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198644

    Software Advisories
    Advisory ID Software Component Link
    USN-5250-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5250-1