CVE-2015-4171
strongswan - security update
EPSS 2.0%
描述
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
如何修補 CVE-2015-4171
要修補 CVE-2015-4171,請將受影響套件升級到下列已修補版本。
- Debian/strongswan—升級至 5.3.1-1 或更新版本
- Debian/strongswan—升級至 4.4.1-5.7 或更新版本
- —升級至 4.5.2-1.5+deb7u7 或更新版本
CVE-2015-4171 正在被利用嗎?
低 — EPSS 為 2.0%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 5.3.1-1
- from 0, < 4.4.1-5.7
- from 0, < 4.5.2-1.5+deb7u7