strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Strongswan Strongswan
cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
|
5.0.2
|
6.1.0
|