USN-5250-1 fixed a vulnerability in strongSwan. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Zhuowei Zhang discovered that stringSwan incorrectly handled EAP authentication. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly bypass client and server authentication.
{
"binaries": [
{
"binary_name": "libstrongswan",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-ike",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-ikev1",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-ikev2",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-nm",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-af-alg",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-agent",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-attr-sql",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-certexpire",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-coupling",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-curl",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-dhcp",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-dnscert",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-dnskey",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-duplicheck",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-aka",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-aka-3gpp2",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-dynamic",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-gtc",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-md5",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-mschapv2",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-peap",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-radius",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-sim",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-sim-file",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-sim-pcsc",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-simaka-pseudonym",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-simaka-reauth",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-simaka-sql",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-tls",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-tnc",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-eap-ttls",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-error-notify",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-farp",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-fips-prf",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-gcrypt",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-gmp",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-ipseckey",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-kernel-libipsec",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-ldap",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-led",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-load-tester",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-lookip",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-mysql",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-ntru",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-openssl",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-pgp",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-pkcs11",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-pubkey",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-radattr",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-soup",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-sql",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-sqlite",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-sshkey",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-systime-fix",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-unbound",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-unity",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-whitelist",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-eap",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-generic",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-noauth",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-pam",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-pt-tls-client",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-starter",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-tnc-base",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-tnc-client",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-tnc-ifmap",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-tnc-pdp",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
},
{
"binary_name": "strongswan-tnc-server",
"binary_version": "5.1.2-0ubuntu2.11+esm2"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"cves": [
{
"id": "CVE-2021-45079",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "high",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:14.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5250-2.json"
{
"binaries": [
{
"binary_name": "charon-cmd",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "libcharon-extra-plugins",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "libstrongswan",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "libstrongswan-extra-plugins",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "libstrongswan-standard-plugins",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-charon",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-ike",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-ikev1",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-ikev2",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-libcharon",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-nm",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-af-alg",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-agent",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-attr-sql",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-certexpire",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-coupling",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-curl",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-dhcp",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-dnscert",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-dnskey",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-duplicheck",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-aka",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-aka-3gpp2",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-dynamic",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-gtc",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-md5",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-mschapv2",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-peap",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-radius",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-sim",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-sim-file",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-sim-pcsc",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-simaka-pseudonym",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-simaka-reauth",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-simaka-sql",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-tls",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-tnc",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-eap-ttls",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-error-notify",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-farp",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-fips-prf",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-gcrypt",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-gmp",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-ipseckey",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-kernel-libipsec",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-ldap",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-led",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-load-tester",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-lookip",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-mysql",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-ntru",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-openssl",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-pgp",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-pkcs11",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-pubkey",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-radattr",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-soup",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-sql",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-sqlite",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-sshkey",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-systime-fix",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-unbound",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-unity",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-whitelist",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-eap",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-generic",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-noauth",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-plugin-xauth-pam",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-starter",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-tnc-base",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-tnc-client",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-tnc-ifmap",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-tnc-pdp",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
},
{
"binary_name": "strongswan-tnc-server",
"binary_version": "5.3.5-1ubuntu3.8+esm2"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"cves": [
{
"id": "CVE-2021-45079",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "high",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:16.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5250-2.json"