Gentoo Archives: gentoo-announce

From: Alex Legler <a3li@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200905-03 ] IPSec Tools: Denial of Service
Date: Sun, 24 May 2009 13:24:11
Message-Id: 1243171239.23024.4.camel@localhost
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200905-03
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: IPSec Tools: Denial of Service
9 Date: May 24, 2009
10 Bugs: #267135
11 ID: 200905-03
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple errors in the IPSec Tools racoon daemon might allow remote
19 attackers to cause a Denial of Service.
20
21 Background
22 ==========
23
24 The IPSec Tools are a port of KAME's IPsec utilities to the Linux-2.6
25 IPsec implementation. They include racoon, an Internet Key Exchange
26 daemon for automatically keying IPsec connections.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 net-firewall/ipsec-tools < 0.7.2 >= 0.7.2
35
36 Description
37 ===========
38
39 The following vulnerabilities have been found in the racoon daemon as
40 shipped with IPSec Tools:
41
42 * Neil Kettle reported that racoon/isakmp_frag.c is prone to a
43 null-pointer dereference (CVE-2009-1574).
44
45 * Multiple memory leaks exist in (1) the eay_check_x509sign()
46 function in racoon/crypto_openssl.c and (2) racoon/nattraversal.c
47 (CVE-2009-1632).
48
49 Impact
50 ======
51
52 A remote attacker could send specially crafted fragmented ISAKMP
53 packets without a payload or exploit vectors related to X.509
54 certificate authentication and NAT traversal, possibly resulting in a
55 crash of the racoon daemon.
56
57 Workaround
58 ==========
59
60 There is no known workaround at this time.
61
62 Resolution
63 ==========
64
65 All IPSec Tools users should upgrade to the latest version:
66
67 # emerge --sync
68 # emerge --ask --oneshot --verbose ">=net-firewall/ipsec-tools-0.7.2"
69
70 References
71 ==========
72
73 [ 1 ] CVE-2009-1574
74 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1574
75 [ 2 ] CVE-2009-1632
76 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1632
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-200905-03.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 http://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2009 Gentoo Foundation, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature