Login
Newsletter
Werbung

Sicherheit: Denial of Service in IPsec-Tools
Aktuelle Meldungen Distributionen
Name: Denial of Service in IPsec-Tools
ID: USN-2623-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS
Datum: Mo, 1. Juni 2015, 22:53
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4047
Applikationen: IPsec-Tools

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============4158795874403901923==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="4WdSrL4k9JpbERKgV009trXJxQ60aMR4v"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--4WdSrL4k9JpbERKgV009trXJxQ60aMR4v
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2623-1
June 01, 2015

ipsec-tools vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

ipsec-tools could be made to crash if it received specially crafted network
traffic.

Software Description:
- ipsec-tools: IPsec tools for Linux

Details:

It was discovered that racoon, the ipsec-tools IKE daemon, incorrectly
handled certain UDP packets. A remote attacker could use this issue to
cause racoon to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
racoon 1:0.8.0-9ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2623-1
CVE-2015-4047

Package Information:
https://launchpad.net/ubuntu/+source/ipsec-tools/1:0.8.0-9ubuntu1.1



--4WdSrL4k9JpbERKgV009trXJxQ60aMR4v
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJVbJMLAAoJEGVp2FWnRL6TVu0P/jwzAfJfuY/2ikwSO9A7OBF7
Pa2OVj2pVWT+zAySrYP910sQv1LGBcCgqOKIuXUXcQc4BfuxJf7BhW58NBu6OkKs
pK9+Zv7yMjDEKIpH13ja9uN6xRTQwrtn9iRpC6iXZGniZpHoouN7FnY0LGZDNOhc
xxbMfQ91sCtWziVqnsMsq6SJn1Yib/YitWygM59gUeCiS0LTaLwkrPexnc3S40eb
g2oyG0X7Q8Bn62DZcURIcScZMYH3SQ3xiHTed/dJ5AYIQeb35xEnlQ/9eYb2UoOj
fOgVsYb3fZcxsXYs6vsC61RTz/ORQq6xmk+Z0krAYgorq170di4lcaRN8+aAdKgC
V57ln2CIJBeFtu8eO6PlW0unETyrT6SK8nadN0E1KBJvBPwIl1rgUdDYF/EH/Dci
mBnX02XTjGpgmEZ4BOFXBzgJxIV183i8jXfRMMAqbWVwOi1BJyv8SpGZDCJPFHaz
y8pX4iqYw0457r497zaj4gaeMpAtTPkeEoBtId35krsVh95A9bqljBGs5RiStdGe
ecNN1SNgTMTyJZUo1xRKz+m4jwj8IZB5vJNaA3eefg3BigjRip1D9l/0SpOmylQk
+6ntt5i4swPC96Kkv0KCF55OZUshQMXmueVIc4dJcXQmzG+HcfDxF6gx4p/rIT2N
4ZHn5B18yaJfY0kucNN8
=q3+l
-----END PGP SIGNATURE-----

--4WdSrL4k9JpbERKgV009trXJxQ60aMR4v--


--===============4158795874403901923==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============4158795874403901923==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung