Denial of Service Vulnerability in strongSwan's gmp Plugin
CVE-2017-9022
7.5HIGH
What is CVE-2017-9022?
The gmp plugin in strongSwan before version 5.5.3 has a security flaw that fails to validate RSA public keys properly when invoking mpz_powm_sec. This oversight allows adversaries to exploit the vulnerability by using specially crafted certificates, which can trigger a floating-point exception and lead to process crashes. As a result, affected systems are susceptible to remote disruptions, compromising their uptime and reliability.
