NEWS: Add info about CVE-2025-62291

This commit is contained in:
Tobias Brunner
2025-10-27 14:02:59 +01:00
committed by Andreas Steffen
parent c687ada6a6
commit 1014d74e4b
+5
View File
@@ -1,6 +1,11 @@
strongswan-6.0.3
----------------
- Fixed a vulnerability in the eap-mschapv2 plugin related to processing Failure
Request packets on the client that can lead to a heap-based buffer overflow
and potentially remote code execution.
This vulnerability has been registered as CVE-2025-62291.
- The new `alert` event for vici is raised for certain error conditions.
- Only plugins with matching version number are loaded by programs.