CVE-2018-5388
published 2018-05-31CVE-2018-5388: In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
4.01%
89.4th percentile
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | strongswan | < strongswan 5.6.3-1 (bookworm) | strongswan 5.6.3-1 (bookworm) |
| strongswan | strongswan | < 5.6.3 | 5.6.3 |
| strongswan | strongswan | >= 0 < 5.6.3-1 | 5.6.3-1 |
| strongswan | strongswan | >= 0 < 5.6.3-1 | 5.6.3-1 |
| strongswan | strongswan | >= 0 < 5.6.3-1 | 5.6.3-1 |
| strongswan | strongswan | >= 0 < 5.6.3-1 | 5.6.3-1 |
| strongswan | strongswan | >= 0 < 5.1.2-0ubuntu2.10 | 5.1.2-0ubuntu2.10 |
| strongswan | strongswan | >= 0 < 5.3.5-1ubuntu3.7 | 5.3.5-1ubuntu3.7 |
| strongswan | strongswan | >= 0 < 5.6.2-1ubuntu2.2 | 5.6.2-1ubuntu2.2 |
| strongswan | strongswan | >= 5.6.3 < 5.6.3 | 5.6.3 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv8.1HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fg62-299p-x79j: In stroke_socket
ghsa_unreviewed·2022-05-13
CVE-2018-5388 [MEDIUM] CWE-124 GHSA-fg62-299p-x79j: In stroke_socket
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
OSV
tomcat7 vulnerabilities
osv·2021-03-15·CVSS 8.1
CVE-2016-5388 tomcat7 vulnerabilities
tomcat7 vulnerabilities
It was discovered that Apache Tomcat 7 did not protect applications from the
presence of untrusted client data in an environment variable. A remote
attacker could possible use this vulnerability to redirect the traffic to an
arbitrary proxy and obtain sensitive information. (CVE-2016-5388)
It was discovered that Apache Tomcat 7 mishandled specially crafted input.
An attacker could use this vulnerability to cause a denial of service.
(CVE-2018-1336)
OSV
strongswan vulnerabilities
osv·2018-09-25·CVSS 7.5
CVE-2018-10811 [HIGH] strongswan vulnerabilities
strongswan vulnerabilities
It was discovered that strongSwan incorrectly handled IKEv2 key derivation.
A remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2018-10811)
Sze Yiu Chau discovered that strongSwan incorrectly handled parsing OIDs in
the gmp plugin. A remote attacker could possibly use this issue to bypass
authorization. (CVE-2018-16151)
Sze Yiu Chau discovered that strongSwan incorrectly handled certain
parameters fields in the gmp plugin. A remote attacker could possibly use
this issue to bypass authorization. (CVE-2018-16152)
It was discovered that strongSwan incorrectly handled the stroke plugin. A
local administrator could use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-
OSV
CVE-2018-5388: In stroke_socket
osv·2018-05-31·CVSS 6.5
CVE-2018-5388 [MEDIUM] CVE-2018-5388: In stroke_socket
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
Ubuntu
strongSwan vulnerabilities
vendor_ubuntu·2018-09-25·CVSS 7.5
CVE-2018-10811 [HIGH] strongSwan vulnerabilities
Title: strongSwan vulnerabilities
Summary: Several security issues were fixed in strongSwan.
It was discovered that strongSwan incorrectly handled IKEv2 key derivation.
A remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2018-10811)
Sze Yiu Chau discovered that strongSwan incorrectly handled parsing OIDs in
the gmp plugin. A remote attacker could possibly use this issue to bypass
authorization. (CVE-2018-16151)
Sze Yiu Chau discovered that strongSwan incorrectly handled certain
parameters fields in the gmp plugin. A remote attacker could possibly use
this issue to bypass authorization. (CVE-2018-16152)
It was discovered that strongSwan incorrectly handled the stroke plugin. A
local administrator could use this issue to c
Red Hat
strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c
vendor_redhat·2018-05-22·CVSS 6.5
CVE-2018-5388 [MEDIUM] CWE-190 strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c
strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
An integer underflow has been discovered in strongSwan VPN's charon server, which could lead to a buffer overflow and consequent crash. A local attacker, with enough privileges to access the Unix Domain Socket /var/run/charon.ctl, could use this vulnerability to crash the charon server.
Mitigation: On Red Hat Enterprise Linux 7 only root has access to /var/run/charon.ctl so you need to be already root to exploit the vulnerability.
Package: strongimcv (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2018-5388: strongswan - In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check cou...
vendor_debian·2018·CVSS 6.5
CVE-2018-5388 [MEDIUM] CVE-2018-5388: strongswan - In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check cou...
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
Scope: local
bookworm: resolved (fixed in 5.6.3-1)
bullseye: resolved (fixed in 5.6.3-1)
forky: resolved (fixed in 5.6.3-1)
sid: resolved (fixed in 5.6.3-1)
trixie: resolved (fixed in 5.6.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5388 strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c
bugzilla·2018-05-23·CVSS 6.5
CVE-2018-5388 [MEDIUM] CVE-2018-5388 strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c
CVE-2018-5388 strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c
A flaw was found in strongSwan VPN's charon server prior to version 5.6.3. In stroke_socket.c, a missing packet length check could allow a integer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. A remote attacker with local user credentials (possibly a normal user in the vpn group, or root) may be able to overflow the buffer and cause a denial of service.
References:
https://www.kb.cert.org/vuls/id/338343
Patch:
https://git.strongswan.org/?p=strongswan.git;a=commitdiff;h=0acd1ab4
Discussion:
Created strongswan tracking bugs for this issue:
Affects: epel-all [bug 1581869]
Affects: fedora-all [bug 1581868]
---
The vulnera
Bugzilla
CVE-2018-5388 strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c [epel-all]
bugzilla·2018-05-23·CVSS 6.5
CVE-2018-5388 [MEDIUM] CVE-2018-5388 strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c [epel-all]
CVE-2018-5388 strongswan: integer underflow leads to buffer overflow and denial of service in stroke_socket.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2018-5388 strongswan: buffer underflow in stroke_socket.c [fedora-all]
bugzilla·2018-05-23·CVSS 6.5
CVE-2018-5388 [MEDIUM] CVE-2018-5388 strongswan: buffer underflow in stroke_socket.c [fedora-all]
CVE-2018-5388 strongswan: buffer underflow in stroke_socket.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00047.htmlhttp://packetstormsecurity.com/files/172833/strongSwan-VPN-Charon-Server-Buffer-Overflow.htmlhttp://www.kb.cert.org/vuls/id/338343http://www.securityfocus.com/bid/104263https://git.strongswan.org/?p=strongswan.git%3Ba=commitdiff%3Bh=0acd1ab4https://security.gentoo.org/glsa/201811-16https://usn.ubuntu.com/3771-1/https://www.debian.org/security/2018/dsa-4229http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00047.htmlhttp://packetstormsecurity.com/files/172833/strongSwan-VPN-Charon-Server-Buffer-Overflow.htmlhttp://www.kb.cert.org/vuls/id/338343http://www.securityfocus.com/bid/104263https://git.strongswan.org/?p=strongswan.git%3Ba=commitdiff%3Bh=0acd1ab4https://security.gentoo.org/glsa/201811-16https://usn.ubuntu.com/3771-1/https://www.debian.org/security/2018/dsa-4229
2018-05-31
Published