Security Advisory ipsec-tools security update

Advisory: RHSA-2004:308-06
Type: Security Advisory
Severity: Important
Issued on: 2004-07-29
Last updated on: 2004-07-29
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0607

Details

An updated ipsec-tools package that fixes verification of X.509
certificates in racoon is now available.

IPSEC uses strong cryptography to provide both authentication and
encryption services.

When configured to use X.509 certificates to authenticate remote hosts,
ipsec-tools versions 0.3.3 and earlier will attempt to verify that host
certificate, but will not abort the key exchange if verification fails.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0607 to this issue.

Users of ipsec-tools should upgrade to this updated package which contains
a backported security patch and is not vulnerable to this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
ipsec-tools-0.2.5-0.5.src.rpm
File outdated by:  RHSA-2008:0849
    0700489b312339d14a6222e7eebf203e
 
IA-32:
ipsec-tools-0.2.5-0.5.i386.rpm
File outdated by:  RHSA-2008:0849
    4c0dc4fbfc6f68e907c3a06c3fd625ed
 
x86_64:
ipsec-tools-0.2.5-0.5.x86_64.rpm
File outdated by:  RHSA-2008:0849
    2657c5d3085d3410f54987ccc58b06ee
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
ipsec-tools-0.2.5-0.5.src.rpm
File outdated by:  RHSA-2008:0849
    0700489b312339d14a6222e7eebf203e
 
IA-32:
ipsec-tools-0.2.5-0.5.i386.rpm
File outdated by:  RHSA-2008:0849
    4c0dc4fbfc6f68e907c3a06c3fd625ed
 
IA-64:
ipsec-tools-0.2.5-0.5.ia64.rpm
File outdated by:  RHSA-2008:0849
    ca2cc5029aa0d5738c3cef27b1a8225d
 
PPC:
ipsec-tools-0.2.5-0.5.ppc.rpm
File outdated by:  RHSA-2008:0849
    46229bd51220c21b29814de8eb673948
ipsec-tools-0.2.5-0.5.ppc64.rpm     8b2a1a54d6bbcdba02ffe2ea7cd23d9c
 
s390:
ipsec-tools-0.2.5-0.5.s390.rpm
File outdated by:  RHSA-2008:0849
    b842137119a55d5ee91ab383c9c9a566
 
s390x:
ipsec-tools-0.2.5-0.5.s390x.rpm
File outdated by:  RHSA-2008:0849
    6d3d63090574e34732bbb3d78cfaf08e
 
x86_64:
ipsec-tools-0.2.5-0.5.x86_64.rpm
File outdated by:  RHSA-2008:0849
    2657c5d3085d3410f54987ccc58b06ee
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
ipsec-tools-0.2.5-0.5.src.rpm
File outdated by:  RHSA-2008:0849
    0700489b312339d14a6222e7eebf203e
 
IA-32:
ipsec-tools-0.2.5-0.5.i386.rpm
File outdated by:  RHSA-2008:0849
    4c0dc4fbfc6f68e907c3a06c3fd625ed
 
IA-64:
ipsec-tools-0.2.5-0.5.ia64.rpm
File outdated by:  RHSA-2008:0849
    ca2cc5029aa0d5738c3cef27b1a8225d
 
x86_64:
ipsec-tools-0.2.5-0.5.x86_64.rpm
File outdated by:  RHSA-2008:0849
    2657c5d3085d3410f54987ccc58b06ee
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
ipsec-tools-0.2.5-0.5.src.rpm
File outdated by:  RHSA-2008:0849
    0700489b312339d14a6222e7eebf203e
 
IA-32:
ipsec-tools-0.2.5-0.5.i386.rpm
File outdated by:  RHSA-2008:0849
    4c0dc4fbfc6f68e907c3a06c3fd625ed
 
IA-64:
ipsec-tools-0.2.5-0.5.ia64.rpm
File outdated by:  RHSA-2008:0849
    ca2cc5029aa0d5738c3cef27b1a8225d
 
x86_64:
ipsec-tools-0.2.5-0.5.x86_64.rpm
File outdated by:  RHSA-2008:0849
    2657c5d3085d3410f54987ccc58b06ee
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

126568 - racoon authentication bug


References


Keywords

IKE, racoon, X.509


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/