A vulnerability in strongSwan IPsec that leads to remote code execution.

A vulnerability (CVE-2023-41913) has been identified in strongSwan, a VPN package based on the IPSec protocol, used in Linux, Android, FreeBSD, and macOS, which could be exploited for remote code execution by an attacker. This vulnerability is caused by an error in the charon-tkm process implementing the key exchange protocol (IKE) based on TKMv2 (Trusted Key Manager), leading to a buffer overflow when processing specially crafted DH (Diffie-Hellman) scheme values. The vulnerability only manifests in systems using charon-tkm and in releases of strongSwan from version 5.3.0 onwards. The issue has been addressed in the strongSwan 5.9.12 update. Patches have also been prepared to fix the vulnerability in branches starting from 5.3.x.

The error is caused by the absence of a size check for public Diffie-Hellman values before copying them into a fixed-size buffer on the stack. The overflow can be triggered by sending a specially crafted IKE_SA_INIT message, which is processed without authentication. In older versions of strongSwan, the size check was performed in the KE payload (Key Exchange) handler, but in version 5.3.0, changes were made that moved the size check for public values to the DH (Diffie-Hellman) protocol handler and added standard functions to simplify the verification of known DH groups. Due to oversight, new verification functions were omitted in the charon-tkm process, which acts as a proxy between the IKE process and the TKM (Trusted Key Manager), resulting in unchecked values being passed to the memcpy() function, allowing up to 10,000 bytes of data to be written to a 512-byte buffer.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster