|
|
| |
|
| |
strongswan: authentication bypass
| Package(s): | strongswan |
CVE #(s): | CVE-2012-2388
|
| Created: | May 31, 2012 |
Updated: | April 30, 2013 |
| Description: |
From the Debian advisory:
An authentication bypass issue was discovered by the Codenomicon CROSS
project in strongSwan, an IPsec-based VPN solution. When using
RSA-based setups, a missing check in the gmp plugin could allow an
attacker presenting a forged signature to successfully authenticate
against a strongSwan responder.
|
| Alerts: |
|
( Log in to post comments)
|
|
|