• [SECURITY] [DSA 5056-1] strongswan security update

    From Yves-Alexis Perez@21:1/5 to All on Mon Jan 24 18:20:02 2022
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5056-1 security@debian.org https://www.debian.org/security/ Yves-Alexis Perez January 24, 2022 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : strongswan
    CVE ID : CVE-2021-45079

    Zhuowei Zhang discovered a bug in the EAP authentication client code of strongSwan, an IKE/IPsec suite, that may allow to bypass the client and in some scenarios even the server authentication, or could lead to a denial-of-service attack.

    When using EAP authentication (RFC 3748), the successful completion of the authentication is indicated by an EAP-Success message sent by the server to the client. strongSwan's EAP client code handled early EAP-Success messages incorrectly, either crashing the IKE daemon or concluding the EAP method prematurely.

    End result depend on the used configuration, more details can be found in upstream advisory at https://www.strongswan.org/blog/2022/01/24/strongswan-vulnerability-(cve-2021-45079).html

    For the oldstable distribution (buster), this problem has been fixed
    in version 5.7.2-1+deb10u2.

    For the stable distribution (bullseye), this problem has been fixed in
    version 5.9.1-1+deb11u2.

    We recommend that you upgrade your strongswan packages.

    For the detailed security status of strongswan please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/strongswan

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAmHu3ToACgkQ3rYcyPpX RFu9uAf/TE295wtzcjBDiCR/IcBxmkarSZ3I/6vG+z3YtAPMm7Y5bXhIIRd5jO0R WEK4b9seQx8MM9xwuot/mCtV8gcWimLn9cmfrvXAOgAqTCn3LyxoJ/b5A4FcQ+tf wr70fjxouWJY13gUyv1plJEe3kCztBtE2S0HeFGQ0sux5FqJArZD3tBmaY9d9+Ux jGDSf/w2ZCtvmt2JHay3Ts3QZR9AdNWstwRcCZy5E7AwByFvM4mWnzEHus2t9emb BPwO2S/vCXeV9ax1NxNBQhhPN4cITBuPB0Wl+TweuptuSmb1sLYr3BsG/k+SDVix ji2X+IlAESpAPWnMy2V9rS8eeyjs1A==
    =H6Ag
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)