Oval Definition:oval:com.ubuntu.precise:def:20154171000
Revision Date:2015-06-10Version:1
Title:CVE-2015-4171 on Ubuntu 12.04 LTS (precise) - high.
Description:strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-4171
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'strongswan' package in precise is affected and needs fixing.
  • BACK