Denial of Service Vulnerability in strongSwan's ASN.1 Parser
CVE-2017-9023
7.5HIGH
What is CVE-2017-9023?
The ASN.1 parser within strongSwan versions before 5.5.3 has a vulnerability that improperly manages CHOICE types when the x509 plugin is activated. This flaw can be exploited remotely, potentially leading to a denial of service condition characterized by an infinite loop when a specially crafted certificate is processed. This situation highlights a critical area of concern for users depending on strongSwan for secure communications, necessitating prompt updates to safeguard against such attacks.
