The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Fedoraproject Subscribe
Siemens Subscribe
Cp 1543-1 Subscribe
Cp 1543-1 Firmware Subscribe
Scalance Sc622-2c Subscribe
Scalance Sc622-2c Firmware Subscribe
Scalance Sc632-2c Subscribe
Scalance Sc632-2c Firmware Subscribe
Scalance Sc636-2c Subscribe
Scalance Sc636-2c Firmware Subscribe
Scalance Sc642-2c Subscribe
Scalance Sc642-2c Firmware Subscribe
Scalance Sc646-2c Subscribe
Scalance Sc646-2c Firmware Subscribe
Simatic Cp 1242-7 Gprs V2 Subscribe
Simatic Cp 1242-7 Gprs V2 Firmware Subscribe
Simatic Cp 1243-1 Subscribe
Simatic Cp 1243-1 Firmware Subscribe
Simatic Cp 1243-7 Lte\/us Subscribe
Simatic Cp 1243-7 Lte\/us Firmware Subscribe
Simatic Cp 1542sp-1 Subscribe
Simatic Cp 1542sp-1 Firmware Subscribe
Simatic Cp 1542sp-1 Irc Subscribe
Simatic Cp 1542sp-1 Irc Firmware Subscribe
Simatic Cp 1543sp-1 Subscribe
Simatic Cp 1543sp-1 Firmware Subscribe
Simatic Net Cp1243-7 Lte Eu Subscribe
Simatic Net Cp1243-7 Lte Eu Firmware Subscribe
Simatic Net Cp 1243-8 Irc Subscribe
Simatic Net Cp 1243-8 Irc Firmware Subscribe
Simatic Net Cp 1545-1 Subscribe
Simatic Net Cp 1545-1 Firmware Subscribe
Sinema Remote Connect Server Subscribe
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Subscribe
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Firmware Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware Subscribe
Siplus Net Cp 1543-1 Subscribe
Siplus Net Cp 1543-1 Firmware Subscribe
Siplus S7-1200 Cp 1243-1 Subscribe
Siplus S7-1200 Cp 1243-1 Firmware Subscribe
Siplus S7-1200 Cp 1243-1 Rail Subscribe
Siplus S7-1200 Cp 1243-1 Rail Firmware Subscribe
Strongswan Subscribe
Strongswan Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2788-1 strongswan security update
Debian DSA Debian DSA DSA-4989-1 strongswan security update
EUVD EUVD EUVD-2021-28981 The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Ubuntu USN Ubuntu USN USN-5111-1 strongSwan vulnerabilities
Ubuntu USN Ubuntu USN USN-5111-2 strongSwan vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:22:25.655Z

Reserved: 2021-10-04T00:00:00

Link: CVE-2021-41991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-18T14:15:10.333

Modified: 2024-11-21T06:27:02.090

Link: CVE-2021-41991

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-10-18T00:00:00Z

Links: CVE-2021-41991 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses