CVE-2021-41991

Name
CVE-2021-41991
Description
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-(cve-2021-41991).html
MISC https://github.com/strongswan/strongswan/releases/tag/5.9.4
DEBIAN https://www.debian.org/security/2021/dsa-4989
MLIST https://lists.debian.org/debian-lts-announce/2021/10/msg00014.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQSQ3BEC22NF4NCDZVCT4P3Q2ZIAJXGJ/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5FJSATD2R2XHTG4P63GCMQ2N7EWKMME5/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y3TQ32JLJOBJDB2EJKSX2PBPB5NFG2D4/
Patch https://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdf

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* strongswan >= 4.2.10 < 5.9.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
strongswan 3.11-main 5.8.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
strongswan 3.12-main 5.8.4-r3 Natanael Copa <ncopa@alpinelinux.org> fixed
strongswan 3.15-main 5.9.1-r4 Natanael Copa <ncopa@alpinelinux.org> fixed
strongswan 3.14-main 5.9.1-r3 Natanael Copa <ncopa@alpinelinux.org> fixed
strongswan 3.13-main 5.9.1-r2 Natanael Copa <ncopa@alpinelinux.org> fixed