CVE-2018-16152 | Exponent strongSwan up to up to 4.x/5.6. IKEv2 Authentication gmp_rsa_public_key.c verify_emsa_pkcs1_signature digestAlgorithmparameters signature verification (USN-3771-1 / Nessus ID 117715)
A vulnerability labeled as critical has been found in Exponent strongSwan up to up to 4.x/5.6.. This affects the function verify_emsa_pkcs1_signature of the file gmp_rsa_public_key.c of the component IKEv2 Authentication. Such manipulation of the argument digestAlgorithmparameters as part of RSA Signature leads to improper verification of cryptographic signature.
This vulnerability is traded as CVE-2018-16152. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.