* strongSwan 5.9.9 released, fixing CVE-2023-26463
@ 2023-03-05 14:44 Peter Müller
2023-03-06 12:54 ` Adolf Belka
0 siblings, 1 reply; 2+ messages in thread
From: Peter Müller @ 2023-03-05 14:44 UTC (permalink / raw)
To: development
[-- Attachment #1: Type: text/plain, Size: 644 bytes --]
Hello development folks,
just for everyone's information:
https://www.strongswan.org/blog/2023/03/02/strongswan-vulnerability-(cve-2023-26463).html
https://www.strongswan.org/blog/2023/01/03/strongswan-5.9.9-released.html
To the best of my understanding, IPFire is affected by CVE-2023-26463
(since the respective strongSwan plugins are loaded), but not vulnerable,
since such authentication cannot be configured via the web interface.
However, any installations running customized IPsec connections might be
affected by this.
Any volounteers for updating strongSwan? Thank you in advance. :-)
All the best,
Peter Müller
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: strongSwan 5.9.9 released, fixing CVE-2023-26463
2023-03-05 14:44 strongSwan 5.9.9 released, fixing CVE-2023-26463 Peter Müller
@ 2023-03-06 12:54 ` Adolf Belka
0 siblings, 0 replies; 2+ messages in thread
From: Adolf Belka @ 2023-03-06 12:54 UTC (permalink / raw)
To: development
[-- Attachment #1: Type: text/plain, Size: 827 bytes --]
Hi Peter,
On 05/03/2023 15:44, Peter Müller wrote:
> Hello development folks,
>
> just for everyone's information:
>
> https://www.strongswan.org/blog/2023/03/02/strongswan-vulnerability-(cve-2023-26463).html
> https://www.strongswan.org/blog/2023/01/03/strongswan-5.9.9-released.html
>
> To the best of my understanding, IPFire is affected by CVE-2023-26463
> (since the respective strongSwan plugins are loaded), but not vulnerable,
> since such authentication cannot be configured via the web interface.
> However, any installations running customized IPsec connections might be
> affected by this.
>
> Any volounteers for updating strongSwan? Thank you in advance. :-)
I will pick this up if someone else hasn't already started working on it.
Regards,
Adolf.
> All the best,
> Peter Müller
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2023-03-06 12:54 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-03-05 14:44 strongSwan 5.9.9 released, fixing CVE-2023-26463 Peter Müller
2023-03-06 12:54 ` Adolf Belka
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox