Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200705-09 ] IPsec-Tools: Denial of Service
Date: Tue, 08 May 2007 13:45:34
Message-Id: 20070508131107.GB22741@falco.falcal.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200705-09
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: IPsec-Tools: Denial of Service
9 Date: May 08, 2007
10 Bugs: #173219
11 ID: 200705-09
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 IPsec-Tools contains a vulnerability that allows a remote attacker to
19 crash the IPsec tunnel.
20
21 Background
22 ==========
23
24 IPsec-Tools is a port of KAME's implementation of the IPsec utilities.
25 It contains a collection of network monitoring tools, including racoon,
26 ping, and ping6.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 net-firewall/ipsec-tools < 0.6.7 >= 0.6.7
35
36 Description
37 ===========
38
39 The isakmp_info_recv() function in src/racoon/isakmp_inf.c does not
40 always check that DELETE (ISAKMP_NPTYPE_D) and NOTIFY (ISAKMP_NPTYPE_N)
41 packets are encrypted.
42
43 Impact
44 ======
45
46 A remote attacker could send a specially crafted IPsec message to one
47 of the two peers during the beginning of phase 1, resulting in the
48 termination of the IPsec exchange.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All IPsec-Tools users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=net-firewall/ipsec-tools-0.6.7"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2007-1841
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1841
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-200705-09.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 http://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2007 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/2.5