Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2009-0402

Опубликовано: 30 мар. 2009
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2009-0402: openswan security update (IMPORTANT)

[2.6.14-1.2]

  • security update (CVE-2009-0790, CVE-2008-4190) Resolves: CVE-2009-0790, CVE-2008-4190

Обновленные пакеты

Oracle Linux 5

Oracle Linux x86_64

openswan

2.6.14-1.el5_3.2

openswan-doc

2.6.14-1.el5_3.2

Oracle Linux i386

openswan

2.6.14-1.el5_3.2

openswan-doc

2.6.14-1.el5_3.2

Связанные CVE

Связанные уязвимости

ubuntu
около 16 лет назад

The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.

redhat
около 16 лет назад

The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.

nvd
около 16 лет назад

The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.

debian
около 16 лет назад

The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.2 ...

ubuntu
больше 16 лет назад

The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.