SUSE-SU-2013:1866-1 -- Security update for strongswan
Description:
This strongswan update fixes security issues and bugs: * CVE-2013-5018: Specially crafted XAuth usernames andEAP identities could cause a crash in strongswan. * CVE-2013-6075: A crafted ID packet can be used byremote attackers to crash the server or potentially gainauthentication privileges under certain circumstances.Additionally, a bug in route recursion limits was fixed: * Charon segfaults when left=%any / recursion limit.(bnc#840826)Security Issues: * CVE-2013-5018