Summary: | <net-vpn/strongswan-5.6.3: integer underflow leads to buffer overflow and denial of service in stroke_socket.c (CVE-2018-5388) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Kristian Fiskerstrand (RETIRED) <k_f> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | bkohler, patrick |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.kb.cert.org/vuls/id/338343 | ||
Whiteboard: | B3 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- |
Description
Kristian Fiskerstrand (RETIRED)
2018-05-23 16:26:27 UTC
strongswan-5.6.3 addressing a number of bugs and vulnerabilities was released on 2018/05/28. Can you please push to the stable tree? -- Regards, Mick Please bump this version and target for stable soon Added to an existing GLSA request. This issue was resolved and addressed in GLSA 201811-16 at https://security.gentoo.org/glsa/201811-16 by GLSA coordinator Aaron Bauman (b-man). |