=========================================================================Ubuntu Security Notice USN-2628-1
June 08, 2015

strongswan vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.10
- Ubuntu 14.04 LTS

Summary:

strongSwan could be made to expose sensitive information over the network.

Software Description:
- strongswan: IPsec VPN solution

Details:

Alexander E. Patrakov discovered that strongSwan incorrectly handled
certain IKEv2 setups. A malicious server could possibly use this issue to
obtain user credentials.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  strongswan-ike                  5.1.2-0ubuntu5.2

Ubuntu 14.10:
  strongswan-ike                  5.1.2-0ubuntu3.3

Ubuntu 14.04 LTS:
  strongswan-ike                  5.1.2-0ubuntu2.3

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2628-1
  CVE-2015-4171

Package Information:
  https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu5.2
  https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu3.3
  https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.3


Ubuntu 2628-1: strongSwan vulnerability

June 8, 2015
strongSwan could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: strongswan-ike 5.1.2-0ubuntu5.2 Ubuntu 14.10: strongswan-ike 5.1.2-0ubuntu3.3 Ubuntu 14.04 LTS: strongswan-ike 5.1.2-0ubuntu2.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2628-1

CVE-2015-4171

Severity
June 08, 2015

Package Information

https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu5.2 https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu3.3 https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.3

Related News