ASA-201802-10 log generated external raw

[ASA-201802-10] strongswan: denial of service
Arch Linux Security Advisory ASA-201802-10 ========================================== Severity: Medium Date : 2018-02-21 CVE-ID : CVE-2018-6459 Package : strongswan Type : denial of service Remote : Yes Link : Summary ======= The package strongswan before version 5.6.2-1 is vulnerable to denial of service. Resolution ========== Upgrade to 5.6.2-1. # pacman -Syu "strongswan>=5.6.2-1" The problem has been fixed upstream in version 5.6.2. Workaround ========== None. Description =========== The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c before strongSwan 5.6.2 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter. Impact ====== A remote attacker is able to crash the application by providing a maliciously-crafted signature. References ==========