Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1899-1] New strongswan packages fix denial of service (

    From Florian Weimer@1:229/2 to All on Fri Oct 2 20:50:07 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1899-1 [email protected] http://www.debian.org/security/ Florian Weimer October 02, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : strongswan
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2009-1957 CVE-2009-1958 CVE-2009-2185 CVE-2009-2661
    Debian Bug : 531612 533837 540144

    Several remote vulnerabilities have been discovered in strongswan, an implementation of the IPSEC and IKE protocols. The Common
    Vulnerabilities and Exposures project identifies the following
    problems:

    CVE-2009-1957
    CVE-2009-1958

    The charon daemon can crash when processing certain crafted IKEv2
    packets. (The old stable distribution (etch) was not affected by
    these two problems because it lacks IKEv2 support.)

    CVE-2009-2185
    CVE-2009-2661

    The pluto daemon could crash when processing a crafted X.509
    certificate.

    For the old stable distribution (etch), these problems have been fixed
    in version 2.8.0+dfsg-1+etch2.

    For the stable distribution (lenny), these problems have been fixed in
    version 4.2.4-5+lenny3.

    For the unstable distribution (sid), these problems have been fixed in
    version 4.3.2-1.1.

    We recommend that you upgrade your strongswan packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2.diff.gz
    Size/MD5 checksum: 58570 945cc03b76743138f14b9719a204fedb
    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg.orig.tar.gz
    Size/MD5 checksum: 3155518 8b9ac905b9bcd41fb826e3d67e90a33d
    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2.dsc
    Size/MD5 checksum: 811 6787c4f1c81bc390d2d4c5ef7cd1f004

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_alpha.deb
    Size/MD5 checksum: 1210988 0ea0beeecfd0569a417cdd7a8890afa0

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_amd64.deb
    Size/MD5 checksum: 1100154 e7975b7c9593e6813b1ab2391488fd5e

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_arm.deb
    Size/MD5 checksum: 1070960 49bb60a09eeffd0b82abea6a742099ea

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_hppa.deb
    Size/MD5 checksum: 1133960 e2fd0221197dfc3624ff95095453883a

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_i386.deb
    Size/MD5 checksum: 1054160 3859569cbea184e01cb17158458a86e0

    ia64 architecture (Intel ia64)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_ia64.deb
    Size/MD5 checksum: 1453188 ef4f77c2fafc736399b1cf24eba13ab2

    mips architecture (MIPS (Big Endian))

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_mips.deb
    Size/MD5 checksum: 1124320 b163fda8163d818f160658bc2b1a764c

    mipsel architecture (MIPS (Little Endian))

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_mipsel.deb
    Size/MD5 checksum: 1129922 d6ae9af171b053e87e4cff2ed30588f1

    powerpc architecture (PowerPC)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_powerpc.deb
    Size/MD5 checksum: 1097810 c9f14e78602cf64488374ff27edb9fa4

    s390 architecture (IBM S/390)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_s390.deb
    Size/MD5 checksum: 1083894 3dac1f759f83817c674e29a9db14dc48

    sparc architecture (Sun SPARC/UltraSPARC)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_2.8.0+dfsg-1+etch2_sparc.deb
    Size/MD5 checksum: 1030670 e52adc5269d580dd987d1a6a6d031872

    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3.diff.gz
    Size/MD5 checksum: 61133 b619f96758667d0968c5572c3014d8be
    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3.dsc
    Size/MD5 checksum: 1602 1ea34a8afadc1d588b11d89d9e40a12b
    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4.orig.tar.gz
    Size/MD5 checksum: 3295212 92ddfaedd6698bc6640927def271d476

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3_alpha.deb
    Size/MD5 checksum: 1301924 9b04ce068a381ae22f56649c68651986

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3_amd64.deb
    Size/MD5 checksum: 1180738 035f9bb4259a1e3f2399680a1683a98f

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3_arm.deb
    Size/MD5 checksum: 1028530 f28fcfb750422e4f586510cd7f9f911a

    armel architecture (ARM EABI)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3_armel.deb
    Size/MD5 checksum: 1035544 88390cad9b508b2c8fad0aa35dc8239e

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3_hppa.deb
    Size/MD5 checksum: 1217010 94c648fa6a84688768e9b1a879a9f2db

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/s/strongswan/strongswan_4.2.4-5+lenny3_i386.deb
    Size/MD5 checksum: 1099208 348f57f1abb9b9c29f7ce63454b6b52a


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 155:19:15
    Calls: 12,092
    Files: 15,000
    Messages: 6,517,703

© >>> Magnum BBS <<<, 2026