Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 5.0: DSA-1899-1 Critical: StrongSwan Denial of Service Issues

debian
Calendar Grey October 2, 2009
Debian Logo
Mitigating various external security weaknesses in strongswan through software revisions to prevent Denial of Service threats on Debian platforms.
Several remote vulnerabilities have been discovered in strongswan, an implementation of the IPSEC and IKE protocols

Summary

Several remote vulnerabilities have been discovered in strongswan, an
implementation of the IPSEC and IKE protocols. The Common
Vulnerabilities and Exposures project identifies the following
problems:

CVE-2009-1957
CVE-2009-1958

The charon daemon can crash when processing certain crafted IKEv2
packets. (The old stable distribution (etch) was not affected by
these two problems because it lacks IKEv2 support.)

CVE-2009-2185
CVE-2009-2661

The pluto daemon could crash when processing a crafted X.509
certificate.

For the old stable distribution (etch), these problems have been fixed
in version 2.8.0+dfsg-1+etch2.

For the stable distribution (lenny), these problems have been fixed in
version 4.2.4-5+lenny3.

For the unstable distribution (sid), these problems have been fixed in
version 4.3.2-1.1.

We recommend that you upgrade your strongswan packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: strongswan

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here