Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1804-1] New ipsec-tools packages fix denial of service

    From Nico Golde@1:229/2 to All on Wed May 20 16:20:10 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - -------------------------------------------------------------------------- Debian Security Advisory DSA-1804-1 [email protected] http://www.debian.org/security/ Nico Golde
    May 20th, 2009 http://www.debian.org/security/faq
    - --------------------------------------------------------------------------

    Package : ipsec-tools
    Vulnerability : null pointer dereference, memory leaks
    Problem type : remote
    Debian-specific: no
    Debian bug : 527634 528933
    CVE ID : CVE-2009-1574 CVE-2009-1632

    Several remote vulnerabilities have been discovered in racoon, the Internet Key Exchange daemon of ipsec-tools. The The Common Vulnerabilities and Exposures project identified the following problems:

    Neil Kettle discovered a NULL pointer dereference on crafted fragmented packets that contain no payload. This results in the daemon crashing which can be used for denial of service attacks (CVE-2009-1574).

    Various memory leaks in the X.509 certificate authentication handling and the NAT-Traversal keepalive implementation can result in memory exhaustion and
    thus denial of service (CVE-2009-1632).


    For the oldstable distribution (etch), this problem has been fixed in
    version 0.6.6-3.1etch3.

    For the stable distribution (lenny), this problem has been fixed in
    version 0.7.1-1.3+lenny2.

    For the testing distribution (squeeze), this problem will be fixed soon.

    For the unstable distribution (sid), this problem has been fixed in
    version 1:0.7.1-1.5.


    We recommend that you upgrade your ipsec-tools packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Debian (oldstable)
    - ------------------

    Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3.dsc
    Size/MD5 checksum: 722 8b561cf84ac9c46ec07b037ce3ad06f1
    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3.diff.gz
    Size/MD5 checksum: 49875 7444fb4ad448ccfffe878801a2b88d2e

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_amd64.deb
    Size/MD5 checksum: 343790 9cee9f8c479a3a2952d2913d7bdc4c5d
    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_amd64.deb
    Size/MD5 checksum: 89184 5ccd4554eec28da6d933dc20a8a39393

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_arm.deb
    Size/MD5 checksum: 325706 9ce7988b74bccee252be7dac7ac8b5f7
    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_arm.deb
    Size/MD5 checksum: 89748 513ded0e4a33200710444e1bf4ab67d8

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_hppa.deb
    Size/MD5 checksum: 353066 c56644b426ae945ca420d4ca37fc3f2a
    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_hppa.deb
    Size/MD5 checksum: 94092 80b46b6fd60e857c84c588432b098957

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_i386.deb
    Size/MD5 checksum: 330258 b905d30958bd5c51d355f286f81b8be1
    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_i386.deb
    Size/MD5 checksum: 85046 294ccbc4b51e4942edaeec7cd746dfa3

    ia64 architecture (Intel ia64)

    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_ia64.deb
    Size/MD5 checksum: 113356 111f0daa2075584c100efc9c11ecef73
    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_ia64.deb
    Size/MD5 checksum: 468296 bd4d69b5e0d4ee39ec564e1304f7649c

    mips architecture (MIPS (Big Endian))

    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_mips.deb
    Size/MD5 checksum: 89018 b6af57d65d43a7433132bee9657ba608
    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_mips.deb
    Size/MD5 checksum: 344558 aba2d85d5196c2a46555ad9e478d338a

    mipsel architecture (MIPS (Little Endian))

    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_mipsel.deb
    Size/MD5 checksum: 346856 97e04d97bdd55f852392d7461bad7f4d
    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_mipsel.deb
    Size/MD5 checksum: 90308 9e780cda3df3384d0f1e33637d003f21

    powerpc architecture (PowerPC)

    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_powerpc.deb
    Size/MD5 checksum: 91048 98174626d8ad1fba940c81001c337a4f
    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_powerpc.deb
    Size/MD5 checksum: 337266 9f636e6d8904103b0096a4eed99e9cae

    s390 architecture (IBM S/390)

    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_s390.deb
    Size/MD5 checksum: 341586 b42ddbad323dcdbd775d502f786ab449
    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_s390.deb
    Size/MD5 checksum: 90750 62d4c3e618a6c69d532b8d8d33bb27b9

    sparc architecture (Sun SPARC/UltraSPARC)

    http://security.debian.org/pool/updates/main/i/ipsec-tools/ipsec-tools_0.6.6-3.1etch3_sparc.deb
    Size/MD5 checksum: 85710 9f1f526be4f2df4eb64d46023d87c6b3
    http://security.debian.org/pool/updates/main/i/ipsec-tools/racoon_0.6.6-3.1etch3_sparc.deb
    Size/MD5 checksum: 317136 38e50e9d97b46b51d12429b9ea727858



    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 146:52:52
    Calls: 12,091
    Calls today: 4
    Files: 15,000
    Messages: 6,517,518

© >>> Magnum BBS <<<, 2026