Mit Stronswan 4.2.14 wurden einige kritische Sicherheitslücken in der SSL-Implementierung beseitigt.
Unter anderem auch die Lücke in der sogenannten Dead Peer Detection:
A vulnerability in the Dead Peer Detection (RFC 3706) code was found by
Gerd v. Egidy of Intra2net AG affecting
all Openswan and strongSwan releases. A malicious (or expired ISAKMP)
R_U_THERE or R_U_THERE_ACK Dead Peer Detection packet can cause the
pluto IKE daemon to crash and restart. No authentication or encryption
is required to trigger this bug. One spoofed UDP packet can cause the
pluto IKE daemon to restart and be unresponsive for a few seconds while
restarting. This DPD null state vulnerability has been officially
registered as CVE-2009-0790 and is fixed by this release.
Stronswan steht hier zum Download bereit.