NEWS: Add info about CVE-2021-45079

This commit is contained in:
Tobias Brunner
2022-01-20 17:25:07 +01:00
parent 64cc9acbf0
commit 4f560557b0
+6
View File
@@ -1,6 +1,12 @@
strongswan-5.9.5
----------------
- Fixed a vulnerability in the EAP client implementation that was caused by
incorrectly handling early EAP-Success messages. It may allow to bypass the
client and in some scenarios even the server authentication, or could lead to
a denial-of-service attack.
This vulnerability has been registered as CVE-2021-45079.
- Using the trusted RSA or ECC Endorsement Key of the TPM 2.0, libtpmtss may now
establish a secure session via RSA encryption or an ephemeral ECDH key
exchange, respectively. The session allows HMAC-based authenticated