Gentoo Archives: gentoo-announce

From: Robert Buchholz <rbu@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200812-03 ] IPsec-Tools: racoon Denial of Service
Date: Tue, 02 Dec 2008 17:46:51
Message-Id: 200812021831.01771.rbu@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200812-03
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: IPsec-Tools: racoon Denial of Service
9 Date: December 02, 2008
10 Bugs: #232831
11 ID: 200812-03
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 IPsec-Tools' racoon is affected by a remote Denial of Service
19 vulnerability.
20
21 Background
22 ==========
23
24 IPsec-Tools is a port of KAME's implementation of the IPsec utilities.
25 It contains a collection of network monitoring tools, including racoon,
26 ping, and ping6.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 net-firewall/ipsec-tools < 0.7.1 >= 0.7.1
35
36 Description
37 ===========
38
39 Two Denial of Service vulnerabilities have been reported in racoon:
40
41 * The vendor reported a memory leak in racoon/proposal.c that can be
42 triggered via invalid proposals (CVE-2008-3651).
43
44 * Krzysztof Piotr Oledzk reported that src/racoon/handler.c does not
45 remove an "orphaned ph1" (phase 1) handle when it has been initiated
46 remotely (CVE-2008-3652).
47
48 Impact
49 ======
50
51 An attacker could exploit these vulnerabilities to cause a Denial of
52 Service.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 All IPsec-Tools users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot -v ">=net-firewall/ipsec-tools-0.7.1"
66
67 References
68 ==========
69
70 [ 1 ] CVE-2008-3651
71 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3651
72 [ 2 ] CVE-2008-3652
73 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3652
74
75 Availability
76 ============
77
78 This GLSA and any updates to it are available for viewing at
79 the Gentoo Security Website:
80
81 http://security.gentoo.org/glsa/glsa-200812-03.xml
82
83 Concerns?
84 =========
85
86 Security is a primary focus of Gentoo Linux and ensuring the
87 confidentiality and security of our users machines is of utmost
88 importance to us. Any security concerns should be addressed to
89 security@g.o or alternatively, you may file a bug at
90 http://bugs.gentoo.org.
91
92 License
93 =======
94
95 Copyright 2008 Gentoo Foundation, Inc; referenced text
96 belongs to its owner(s).
97
98 The contents of this document are licensed under the
99 Creative Commons - Attribution / Share Alike license.
100
101 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature