UbuntuUpdates.org

Package "libstrongswan-extra-plugins"

Name: libstrongswan-extra-plugins

Description:

strongSwan utility and crypto library (extra plugins)

Latest version: 6.0.1-6ubuntu4.2
Release: questing (25.10)
Level: updates
Repository: universe
Head package: strongswan
Homepage: http://www.strongswan.org

Links


Download "libstrongswan-extra-plugins"


Other versions of "libstrongswan-extra-plugins" in Questing

Repository Area Version
base universe 6.0.1-6ubuntu4
security universe 6.0.1-6ubuntu4.2

Changelog

Version: 6.0.1-6ubuntu4.2 2026-03-24 14:07:58 UTC

  strongswan (6.0.1-6ubuntu4.2) questing-security; urgency=medium

  * SECURITY UPDATE: Integer Underflow When Handling EAP-TTLS AVP
    - debian/patches/CVE-2026-25075.patch: prevent crash if AVP length
      header field is invalid in
      src/libcharon/plugins/eap_ttls/eap_ttls_avp.c.
    - CVE-2026-25075

 -- Marc Deslauriers <email address hidden> Wed, 11 Mar 2026 09:13:39 -0400

Source diff to previous version
CVE-2026-25075 strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote att

Version: 6.0.1-6ubuntu4.1 2025-10-29 14:07:23 UTC

  strongswan (6.0.1-6ubuntu4.1) questing-security; urgency=medium

  * SECURITY UPDATE: Buffer Overflow When Handling EAP-MSCHAPv2 Failure
    Requests
    - debian/patches/CVE-2025-62291.patch: fix length check for Failure
      Request packets on the client in
      src/libcharon/plugins/eap_mschapv2/eap_mschapv2.c.
    - CVE-2025-62291

 -- Marc Deslauriers <email address hidden> Tue, 21 Oct 2025 10:11:00 -0400




About   -   Send Feedback to @ubuntu_updates