Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian 3.0 DSA 201-1 Critical: FreeSWAN DoS Kernel Panic Advisory

debian
Calendar Grey December 2, 2002
Debian Logo
A critical alert concerning the DoS weakness in Free/Swan that may cause kernel failures in Debian environments. Promptly upgrading is recommended to strengthen protective protocols.
Free/SWan in Debain does not properly handle certain very short packets and is said to cause a kernel panic.

Summary

Bindview discovered a problem in several IPSEC implementations that do
not properly handle certain very short packets. IPSEC is a set of
security extensions to IP which provide authentication and encryption.
Free/SWan in Debain is affected by this and is said to cause a kernel
panic.

This problem has been fixed in version 1.96-1.4 for the current stable
distribution (woody) and in version 1.99-1 for the unstable
distribution (sid). The old stable distribution (potato) does not
contain Free/SWan packages.

We recommend that you upgrade your freeswan package.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
------------...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: freeswan

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here