Certificate bug in open source IPsec VPN
The strongSwan open source IPsec VPN software potentially accepts invalid digital signatures and certificates for IPsec connections. The developers report that the issue affects versions 4.3.5 up to 5.0.3 – but only if the OpenSSL crypto backend is enabled using --enable-openssl
; the default crypto libraries are not vulnerable.