FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-2944

This CVE name corresponds to:

Entered Topic
2013-05-03 strongSwan -- ECDSA signature verification issue

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-2944
Phase Assigned(20130411)

Description

strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.

References

Source Reference
MISC http://download.strongswan.org/patches/10_openssl_ecdsa_signature_patch/strongswan-4.3.5-5.0.3_openssl_ecdsa_signature.patch
CONFIRM http://www.strongswan.org/blog/2013/04/30/strongswan-5.0.4-released-(cve-2013-2944).html
DEBIAN DSA-2665
SUSE openSUSE-SU-2013:0774
SUSE openSUSE-SU-2013:0873
SUSE openSUSE-SU-2013:0985
BID 59580