CVE-2013-5018: Opensuse

Medium severity, CVSS 4.3. EPSS: 3% chance of exploitation in the next 30 days.

The is_asn1 function in strongSwan 4.1.11 through 5.0.4 does not properly validate the return value of the asn1_length function, which allows remote attackers to cause a denial of service (segmentation fault) via a (1) XAuth username, (2) EAP identity, or (3) PEM encoded file that starts with a 0x04, 0x30, or 0x31 character followed by an ASN.1 length value that triggers an integer overflow.

Affected products

  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Strongswan Strongswan: version 4.1.11 only; version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.4 only

Published 2013-08-28. Last modified 2026-06-16.