• [SECURITY] [DSA 4684-1] libreswan security update

    From Salvatore Bonaccorso@1:229/2 to All on Wed May 13 21:20:02 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4684-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso
    May 13, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : libreswan
    CVE ID : CVE-2020-1763
    Debian Bug : 960458

    Stephan Zeisberg discovered that the libreswan IPsec implementation
    could be forced into a crash/restart via a malformed IKEv1 Informational Exchange packet, resulting in denial of service.

    For the stable distribution (buster), this problem has been fixed in
    version 3.27-6+deb10u1.

    We recommend that you upgrade your libreswan packages.

    For the detailed security status of libreswan please refer to its
    security tracker page at:
    https://security-tracker.debian.org/tracker/libreswan

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl68RM9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RWCw//Te2J/Kk2Jz6o2Ld51VnQAi18+aNRBCd17Qrm8I/uzrzWDExH+5A4s3fk 9NVKUd0Qce/1ceNihmAosr6sGM6EAK04dTX8uKa8024pl/X1hQuxUYUQkoVlHD8r LBgaQzassxmnEjTkkuU5oX60Zzn6AKVoRmNJalHN7b5ribRwKRMwxHrra/NtM0gi 5FUnFqR47Z071I7oM0ib2by+eIWyvXs+Yhrz7iQPtjSvWRbZyxr9hYgUr/GQAygK 7GccDnnaNiGYtzotEOwGZrOi4PsMAIjW7ha5yl+/f69Dk22vQ53gvb5UrVBNrcXm RKcflpLYHMujjGnGQ3b7lW6Gqdyf0grq3gekq9CEaqJT45QVuHpmpTPHxnDSd9MS zCb+r+f8uzRlrfXkz+KdFLnYgrpDH5lw1nAfJdT7pWmUBuC0Em8J6iEd3HcnPW/3 g7juVedr3XfE3RC7wzMtAcPvCvZ2x7yXZCuEkhHftA846EA1Veebk6+GIrgQkaHi iNRoLCJ0mlkMDsEbMUrcxEj1fxP8B0TT+QMRaDdeGhvaX3LeTHJXpW7hBE3fafbO ci0xIOP/FjDwoiHi36Qml1pD933dJtf5gT2EuiRJmVuFfSgsuyvkn7VTabNHcthA IK4YsIv4ud8lRcYF1BbI+zxef6en3aXZrqpHdyp3rEvQWdMXFus=
    =I7dn
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)