Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Critical StrongSwan Authentication Bypass for Ubuntu 15.10, 15.04, 14.04

Ubuntu Large Esm H500
strongSwan could be made to bypass authentication.
=========================================================================Ubuntu Security Notice USN-2811-1
November 16, 2015

strongswan vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS

Summary:

strongSwan could be made to bypass authentication.

Software Description:
- strongswan: IPsec VPN solution

Details:

It was discovered that the strongSwan eap-mschapv2 plugin incorrectly
handled state. A remote attacker could use this issue to bypass
authentication.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  strongswan-plugin-eap-mschapv2  5.1.2-0ubuntu6.2

Ubuntu 15.04:
  strongswan-plugin-eap-mschapv2  5.1.2-0ubuntu5.3

Ubuntu 14.04 LTS:
  strongswan-plugin-eap-mschapv2  5.1.2-0ubuntu2.4

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2811-1
  CVE-2015-8023

Package Information:
  https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu6.2
  https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu5.3
  https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.4


Critical StrongSwan Authentication Bypass for Ubuntu 15.10, 15.04, 14.04

ubuntu
Calendar Grey November 16, 2015
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-2812-1 tackles a vulnerability in strongSwan that could enable unauthorized access across several editions.
strongSwan could be made to bypass authentication.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: strongswan-plugin-eap-mschapv2 5.1.2-0ubuntu6.2 Ubuntu 15.04: strongswan-plugin-eap-mschapv2 5.1.2-0ubuntu5.3 Ubuntu 14.04 LTS: strongswan-plugin-eap-mschapv2 5.1.2-0ubuntu2.4 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2811-1

CVE-2015-8023

Severity
critical
Lowest
Low
Medium
High
Critical

November 16, 2015

Package Information

https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu6.2 https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu5.3 https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here