NEWS: Add info about CVE-2022-40617

This commit is contained in:
Tobias Brunner
2022-10-03 10:48:46 +02:00
parent 1f870ae189
commit b2488db2ce
+4
View File
@@ -1,6 +1,10 @@
strongswan-5.9.8
----------------
- Fixed a vulnerability related to accessing untrusted OCSP URIs and CDPs in
certificates that could lead to a denial-of-service attack.
This vulnerability has been registered as CVE-2022-40617.
- The pki --scep|--scepca commands support the HTTP-based "Simple Certificate
Enrollment Protocol" (RFC 8894 SCEP) replacing the old and long deprecated
scepclient that has been removed.