PT-2018-3465 · Strongswan+3 · Strongswan+3

Sze Yiu Chau

·

Published

2018-09-24

·

Updated

2025-12-03

·

CVE-2018-16151

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: strongSwan versions 4.x through 5.x before 5.7.0
Description: The issue is related to the verify emsa pkcs1 signature() function in the gmp plugin, which does not correctly verify cryptographic signatures. This can allow a remote attacker to forge signatures when small public exponents are used, potentially leading to impersonation when only an RSA signature is used for IKEv2 authentication.
Recommendations: For strongSwan versions 4.x through 5.x before 5.7.0, update to version 5.7.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of small public exponents in RSA signatures until a patch is available.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2384
BDU:2020-01851
CVE-2018-16151
DLA-1522-1
DSA-4305-1
DSA-4309-1
OPENSUSE-SU-2019:2594-1
OPENSUSE-SU-2019:2598-1
OPENSUSE-SU-2019_2594-1
OPENSUSE-SU-2019_2598-1
SUSE-SU-2019:3056-1
SUSE-SU-2019:3266-1
SUSE-SU-2022:14887-1
SUSE-SU-2022_14887-1
USN-3771-1

Affected Products

Alt Linux
Suse
Ubuntu
Strongswan