Gentoo Archives: gentoo-announce

From: Sam James <sam@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202007-21 ] Libreswan: Denial of service
Date: Mon, 27 Jul 2020 00:09:33
Message-Id: 625381E5-C656-4774-A828-96BD2C2E6519@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202007-21
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Libreswan: Denial of service
9 Date: July 27, 2020
10 Bugs: #722696
11 ID: 202007-21
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability in Libreswan could lead to a Denial of Service
19 condition.
20
21 Background
22 ==========
23
24 Libreswan is a free software implementation of the most widely
25 supported and standarized VPN protocol based on (“IPsec”) and the
26 Internet Key Exchange (“IKE”).
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 net-vpn/libreswan < 3.32 >= 3.32
35
36 Description
37 ===========
38
39 As a result of a bug in handling certain bogus encrypted IKEv1, while
40 building a log message that the packet has been dropped, a NULL pointer
41 dereference causes Libreswan to crash and restart when it attempts to
42 log the state name involved.
43
44 Impact
45 ======
46
47 An attacker could cause a possible Denial of Service condition.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Libreswan users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=net-vpn/libreswan-3.32"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2020-1763
66 https://nvd.nist.gov/vuln/detail/CVE-2020-1763
67
68 Availability
69 ============
70
71 This GLSA and any updates to it are available for viewing at
72 the Gentoo Security Website:
73
74 https://security.gentoo.org/glsa/202007-21
75
76 Concerns?
77 =========
78
79 Security is a primary focus of Gentoo Linux and ensuring the
80 confidentiality and security of our users' machines is of utmost
81 importance to us. Any security concerns should be addressed to
82 security@g.o or alternatively, you may file a bug at
83 https://bugs.gentoo.org.
84
85 License
86 =======
87
88 Copyright 2020 Gentoo Foundation, Inc; referenced text
89 belongs to its owner(s).
90
91 The contents of this document are licensed under the
92 Creative Commons - Attribution / Share Alike license.
93
94 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature