[ubuntu/cosmic-proposed] strongswan 5.6.3-1ubuntu3 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Mon Oct 1 19:17:16 UTC 2018


strongswan (5.6.3-1ubuntu3) cosmic; urgency=medium

  * SECURITY UPDATE: Insufficient input validation in gmp plugin
    - debian/patches/strongswan-4.4.0-5.7.0_gmp-pkcs1-overflow.patch: fix
      buffer overflow with very small RSA keys in
      src/libstrongswan/plugins/gmp/gmp_rsa_private_key.c.
    - CVE-2018-17540

Date: Mon, 01 Oct 2018 13:23:59 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/strongswan/5.6.3-1ubuntu3
-------------- next part --------------
Format: 1.8
Date: Mon, 01 Oct 2018 13:23:59 -0400
Source: strongswan
Binary: strongswan libstrongswan libstrongswan-standard-plugins libstrongswan-extra-plugins libcharon-standard-plugins libcharon-extra-plugins strongswan-starter strongswan-libcharon strongswan-charon strongswan-nm strongswan-tnc-ifmap strongswan-tnc-base strongswan-tnc-client strongswan-tnc-server strongswan-tnc-pdp charon-cmd strongswan-pki strongswan-scepclient strongswan-swanctl charon-systemd
Architecture: source
Version: 5.6.3-1ubuntu3
Distribution: cosmic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 charon-cmd - standalone IPsec client
 charon-systemd - strongSwan IPsec client, systemd support
 libcharon-extra-plugins - strongSwan charon library (extra plugins)
 libcharon-standard-plugins - strongSwan charon library (standard plugins)
 libstrongswan - strongSwan utility and crypto library
 libstrongswan-extra-plugins - strongSwan utility and crypto library (extra plugins)
 libstrongswan-standard-plugins - strongSwan utility and crypto library (standard plugins)
 strongswan - IPsec VPN solution metapackage
 strongswan-charon - strongSwan Internet Key Exchange daemon
 strongswan-libcharon - strongSwan charon library
 strongswan-nm - strongSwan plugin to interact with NetworkManager
 strongswan-pki - strongSwan IPsec client, pki command
 strongswan-scepclient - strongSwan IPsec client, SCEP client
 strongswan-starter - strongSwan daemon starter and configuration file parser
 strongswan-swanctl - strongSwan IPsec client, swanctl command
 strongswan-tnc-base - strongSwan Trusted Network Connect's (TNC) - base files
 strongswan-tnc-client - strongSwan Trusted Network Connect's (TNC) - client files
 strongswan-tnc-ifmap - strongSwan plugin for Trusted Network Connect's (TNC) IF-MAP clie
 strongswan-tnc-pdp - strongSwan plugin for Trusted Network Connect's (TNC) PDP
 strongswan-tnc-server - strongSwan Trusted Network Connect's (TNC) - server files
Changes:
 strongswan (5.6.3-1ubuntu3) cosmic; urgency=medium
 .
   * SECURITY UPDATE: Insufficient input validation in gmp plugin
     - debian/patches/strongswan-4.4.0-5.7.0_gmp-pkcs1-overflow.patch: fix
       buffer overflow with very small RSA keys in
       src/libstrongswan/plugins/gmp/gmp_rsa_private_key.c.
     - CVE-2018-17540
Checksums-Sha1:
 08debd25b6ce601cb912e7b5376c996bd9ad58ea 3923 strongswan_5.6.3-1ubuntu3.dsc
 5a0fe61a6b18a8eb798a49dfe3e37022ae13b1c0 139640 strongswan_5.6.3-1ubuntu3.debian.tar.xz
 1ff4ef448223dde295f784a565f2ce40f4471ea2 11216 strongswan_5.6.3-1ubuntu3_source.buildinfo
Checksums-Sha256:
 15d4e5b5055ea9dfb3b5e3d0997ef262b943fd3c49a19afda13da43392b14d65 3923 strongswan_5.6.3-1ubuntu3.dsc
 2c15ee5d9f71c1a3751d0f3aa61ef907f61329e1e23c62a44e7a164238af35af 139640 strongswan_5.6.3-1ubuntu3.debian.tar.xz
 8d87f1434a776528927e348192da20fe1bc87d52035fd51acddab54277dc9b3f 11216 strongswan_5.6.3-1ubuntu3_source.buildinfo
Files:
 e073e3a81657a06bdfa1187ad9b343a5 3923 net optional strongswan_5.6.3-1ubuntu3.dsc
 6e9edbccb59dfbcd7e295aaaa2c364b3 139640 net optional strongswan_5.6.3-1ubuntu3.debian.tar.xz
 45871eccde7af018c43b5fc46af30dcb 11216 net optional strongswan_5.6.3-1ubuntu3_source.buildinfo
Original-Maintainer: strongSwan Maintainers <pkg-swan-devel at lists.alioth.debian.org>


More information about the Cosmic-changes mailing list