strongswan 5.9.1-1ubuntu3.1 source package in Ubuntu
Changelog
strongswan (5.9.1-1ubuntu3.1) impish-security; urgency=medium * SECURITY UPDATE: Integer Overflow in gmp Plugin - debian/patches/CVE-2021-41990.patch: reject RSASSA-PSS params with negative salt length in src/libstrongswan/credentials/keys/signature_params.c, src/libstrongswan/plugins/gmp/gmp_rsa_public_key.c. - CVE-2021-41990 * SECURITY UPDATE: Integer Overflow When Replacing Certificates in Cache - debian/patches/CVE-2021-41991.patch: prevent crash due to integer overflow/sign change in src/libstrongswan/credentials/sets/cert_cache.c. - CVE-2021-41991 -- Marc Deslauriers <email address hidden> Mon, 18 Oct 2021 13:10:30 -0400
Upload details
- Uploaded by:
- Marc Deslauriers
- Uploaded to:
- Impish
- Original maintainer:
- Ubuntu Developers
- Architectures:
- any all
- Section:
- net
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
strongswan_5.9.1.orig.tar.bz2 | 4.4 MiB | a337c9fb63d973b8440827755c784031648bf423b7114a04918b0b00fd42cafb |
strongswan_5.9.1.orig.tar.bz2.asc | 648 bytes | 1ace47734b67260ece386d9f8b2ac8833e9653149af08e87e23df6b7476cf409 |
strongswan_5.9.1-1ubuntu3.1.debian.tar.xz | 125.7 KiB | d4a32418cfaa402c6471e86014de48734df5137c102ca2d82ffc11b8ef3b8cc2 |
strongswan_5.9.1-1ubuntu3.1.dsc | 3.6 KiB | 1364ab41dd524d167a3ecbee043c5bb968a745d29620b1a0da0c20819f52e69c |
Available diffs
Binary packages built by this source
- charon-cmd: No summary available for charon-cmd in ubuntu impish.
No description available for charon-cmd in ubuntu impish.
- charon-cmd-dbgsym: debug symbols for charon-cmd
- charon-systemd: strongSwan IPsec client, systemd support
The strongSwan VPN suite uses the native IPsec stack in the standard
Linux kernel. It supports both the IKEv1 and IKEv2 protocols.
.
This package contains the charon-systemd files.
- charon-systemd-dbgsym: No summary available for charon-systemd-dbgsym in ubuntu impish.
No description available for charon-
systemd- dbgsym in ubuntu impish.
- libcharon-extauth-plugins: No summary available for libcharon-extauth-plugins in ubuntu impish.
No description available for libcharon-
extauth- plugins in ubuntu impish.
- libcharon-extauth-plugins-dbgsym: No summary available for libcharon-extauth-plugins-dbgsym in ubuntu impish.
No description available for libcharon-
extauth- plugins- dbgsym in ubuntu impish.
- libcharon-extra-plugins: strongSwan charon library (extra plugins)
The strongSwan VPN suite uses the native IPsec stack in the standard
Linux kernel. It supports both the IKEv1 and IKEv2 protocols.
.
This package provides extra plugins for the charon library:
- addrblock (Narrow traffic selectors to RFC 3779 address blocks in X.509
certificates)
- certexpire (Export expiration dates of used certificates)
- eap-aka (Generic EAP-AKA protocol handler using different backends)
- eap-gtc (EAP-GTC protocol handler authenticating with XAuth backends)
- eap-identity (EAP-Identity identity exchange algorithm, to use with other
EAP protocols)
- eap-md5 (EAP-MD5 protocol handler using passwords)
- eap-radius (EAP server proxy plugin forwarding EAP conversations to a
RADIUS server)
- eap-tls (EAP-TLS protocol handler, to authenticate with certificates in
EAP)
- eap-tnc (EAP-TNC protocol handler, Trusted Network Connect in a TLS tunnel)
- eap-ttls (EAP-TTLS protocol handler, wraps other EAP methods securely)
- error-notify (Notification about errors via UNIX socket)
- ha (High-Availability clustering)
- kernel-libipsec (Userspace IPsec Backend with TUN devices)
- led (Let Linux LED subsystem LEDs blink on IKE activity)
- lookip (Virtual IP lookup facility using a UNIX socket)
- tnc (Trusted Network Connect)
- unity (Cisco Unity extensions for IKEv1)
- xauth-eap (XAuth backend that uses EAP methods to verify passwords)
- xauth-pam (XAuth backend that uses PAM modules to verify passwords)
- eap-dynamic (EAP proxy plugin that dynamically selects an EAP method
requested/supported by the client (since 5.0.1))
- eap-peap (EAP-PEAP protocol handler, wraps other EAP methods securely)
- libcharon-extra-plugins-dbgsym: No summary available for libcharon-extra-plugins-dbgsym in ubuntu impish.
No description available for libcharon-
extra-plugins- dbgsym in ubuntu impish.
- libstrongswan: strongSwan utility and crypto library
The strongSwan VPN suite uses the native IPsec stack in the standard
Linux kernel. It supports both the IKEv1 and IKEv2 protocols.
.
This package provides the underlying libraries of charon and other strongSwan
components. It is built in a modular way and is extendable through various
plugins.
.
Some default (as specified by the strongSwan projet) plugins are included.
For libstrongswan (cryptographic backends, URI fetchers and database layers):
- aes (AES-128/192/256 cipher software implementation)
- constraints (X.509 certificate advanced constraint checking)
- dnskey (Parse RFC 4034 public keys)
- drbg (NIST SP-800-90A Deterministic Random Bit Generator)
- fips-prf (PRF specified by FIPS, used by EAP-SIM/AKA algorithms)
- gmp (RSA/DH crypto backend based on libgmp)
- hmac (HMAC wrapper using various hashers)
- md5 (MD5 hasher software implementation)
- mgf1 (Mask Generation Functions based on the SHA-1, SHA-256 and SHA-512)
- nonce (Default nonce generation plugin)
- pem (PEM encoding/decoding routines)
- pgp (PGP encoding/decoding routines)
- pkcs1 (PKCS#1 encoding/decoding routines)
- pkcs8 (PKCS#8 decoding routines)
- pkcs12 (PKCS#12 decoding routines)
- pubkey (Wrapper to handle raw public keys as trusted certificates)
- random (RNG reading from /dev/[u]random)
- rc2 (RC2 cipher software implementation)
- revocation (X.509 CRL/OCSP revocation checking)
- sha1 (SHA1 hasher software implementation)
- sha2 (SHA256/SHA384/ SHA512 hasher software implementation)
- sshkey (SSH key decoding routines)
- x509 (Advanced X.509 plugin for parsing/generating X.509 certificates/CRLs
and OCSP messages)
- xcbc (XCBC wrapper using various ciphers)
- attr (Provides IKE attributes configured in strongswan.conf)
- kernel-netlink [linux] (IPsec/Networking kernel interface using Linux
Netlink)
- kernel-pfkey [kfreebsd] (IPsec kernel interface using PF_KEY)
- kernel-pfroute [kfreebsd] (Networking kernel interface using PF_ROUTE)
- resolve (Writes name servers received via IKE to a resolv.conf file or
installs them via resolvconf(8))
- libstrongswan-dbgsym: debug symbols for libstrongswan
- libstrongswan-extra-plugins: strongSwan utility and crypto library (extra plugins)
The strongSwan VPN suite uses the native IPsec stack in the standard
Linux kernel. It supports both the IKEv1 and IKEv2 protocols.
.
This package provides extra plugins for the strongSwan utility and
cryptographic library.
.
Included plugins are:
- af-alg [linux] (AF_ALG Linux crypto API interface, provides
ciphers/hashers/ hmac/xcbc)
- ccm (CCM cipher mode wrapper)
- cmac (CMAC cipher mode wrapper)
- ctr (CTR cipher mode wrapper)
- curl (libcurl based HTTP/FTP fetcher)
- curve25519 (support for Diffie-Hellman group 31 using Curve25519 and
support for the Ed25519 digital signature algorithm for IKEv2)
- gcrypt (Crypto backend based on libgcrypt, provides
RSA/DH/ciphers/ hashers/ rng)
- ldap (LDAP fetching plugin based on libldap)
- ntru (key exchanged based on post-quantum computer NTRU)
- padlock (VIA padlock crypto backend, provides AES128/SHA1)
- pkcs11 (PKCS#11 smartcard backend)
- rdrand (High quality / high performance random source using the Intel
rdrand instruction found on Ivy Bridge processors)
- test-vectors (Set of test vectors for various algorithms)
.
Also included is the libtpmtss library adding support for TPM plugin
(https://wiki.strongswa n.org/projects/ strongswan/ wiki/TpmPlugin)
- libstrongswan-extra-plugins-dbgsym: No summary available for libstrongswan-extra-plugins-dbgsym in ubuntu impish.
No description available for libstrongswan-
extra-plugins- dbgsym in ubuntu impish.
- libstrongswan-standard-plugins: No summary available for libstrongswan-standard-plugins in ubuntu impish.
No description available for libstrongswan-
standard- plugins in ubuntu impish.
- libstrongswan-standard-plugins-dbgsym: debug symbols for libstrongswan-standard-plugins
- strongswan: IPsec VPN solution metapackage
The strongSwan VPN suite uses the native IPsec stack in the standard Linux
kernel. It supports both the IKEv1 and IKEv2 protocols.
.
This metapackage installs the packages required to maintain IKEv1 and IKEv2
connections via ipsec.conf or ipsec.secrets.
- strongswan-charon: No summary available for strongswan-charon in ubuntu impish.
No description available for strongswan-charon in ubuntu impish.
- strongswan-charon-dbgsym: debug symbols for strongswan-charon
- strongswan-libcharon: No summary available for strongswan-libcharon in ubuntu impish.
No description available for strongswan-
libcharon in ubuntu impish.
- strongswan-libcharon-dbgsym: No summary available for strongswan-libcharon-dbgsym in ubuntu impish.
No description available for strongswan-
libcharon- dbgsym in ubuntu impish.
- strongswan-nm: No summary available for strongswan-nm in ubuntu impish.
No description available for strongswan-nm in ubuntu impish.
- strongswan-nm-dbgsym: debug symbols for strongswan-nm
- strongswan-pki: strongSwan IPsec client, pki command
The strongSwan VPN suite uses the native IPsec stack in the standard
Linux kernel. It supports both the IKEv1 and IKEv2 protocols.
.
This package contains the pki tool which allows on to run a simple public key
infrastructure.
- strongswan-pki-dbgsym: No summary available for strongswan-pki-dbgsym in ubuntu impish.
No description available for strongswan-
pki-dbgsym in ubuntu impish.
- strongswan-scepclient: No summary available for strongswan-scepclient in ubuntu impish.
No description available for strongswan-
scepclient in ubuntu impish.
- strongswan-scepclient-dbgsym: No summary available for strongswan-scepclient-dbgsym in ubuntu impish.
No description available for strongswan-
scepclient- dbgsym in ubuntu impish.
- strongswan-starter: No summary available for strongswan-starter in ubuntu impish.
No description available for strongswan-starter in ubuntu impish.
- strongswan-starter-dbgsym: No summary available for strongswan-starter-dbgsym in ubuntu impish.
No description available for strongswan-
starter- dbgsym in ubuntu impish.
- strongswan-swanctl: strongSwan IPsec client, swanctl command
The strongSwan VPN suite uses the native IPsec stack in the standard
Linux kernel. It supports both the IKEv1 and IKEv2 protocols.
.
This package contains the swanctl interface, used to configure a running
charon daemon
- strongswan-swanctl-dbgsym: debug symbols for strongswan-swanctl