The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Strongswan | Strongswan | 5.6.1 (including) | 5.6.1 (including) |
Strongswan | Ubuntu | devel | * |
Strongswan | Ubuntu | upstream | * |