Public bug reported:

With a strongswan server sending a DNS server to the client, a client
running strongswan-nm 5.6.2-1ubuntu2.4 receives random DNS servers. This
could lead to a data leak issue, if one of these random DNS servers
actually _is_ a DNS server and processes the query (or even a security
issue if ths server sends malicious answers).

This was fixed upstream after 5.6.2:
https://git.strongswan.org/?p=strongswan.git;a=commit;h=ee8c25516a97a2c880a8033e1663628b6b05646a

Applying this patch solved the issue.

** Affects: strongswan (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1837704

Title:
  strongswan-nm passes wrong DNS servers to NetworkManager

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1837704/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to