You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa libreswan

Sigurnosni nedostatak programskog paketa libreswan

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LDE

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA512

– ————————————————————————-
Debian Security Advisory DSA-4684-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
May 13, 2020 https://www.debian.org/security/faq
– ————————————————————————-

Package : libreswan
CVE ID : CVE-2020-1763
Debian Bug : 960458

Stephan Zeisberg discovered that the libreswan IPsec implementation
could be forced into a crash/restart via a malformed IKEv1 Informational
Exchange packet, resulting in denial of service.

For the stable distribution (buster), this problem has been fixed in
version 3.27-6+deb10u1.

We recommend that you upgrade your libreswan packages.

For the detailed security status of libreswan please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/libreswan

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
—–BEGIN PGP SIGNATURE—–

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl68RM9fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0RWCw//Te2J/Kk2Jz6o2Ld51VnQAi18+aNRBCd17Qrm8I/uzrzWDExH+5A4s3fk
9NVKUd0Qce/1ceNihmAosr6sGM6EAK04dTX8uKa8024pl/X1hQuxUYUQkoVlHD8r
LBgaQzassxmnEjTkkuU5oX60Zzn6AKVoRmNJalHN7b5ribRwKRMwxHrra/NtM0gi
5FUnFqR47Z071I7oM0ib2by+eIWyvXs+Yhrz7iQPtjSvWRbZyxr9hYgUr/GQAygK
7GccDnnaNiGYtzotEOwGZrOi4PsMAIjW7ha5yl+/f69Dk22vQ53gvb5UrVBNrcXm
RKcflpLYHMujjGnGQ3b7lW6Gqdyf0grq3gekq9CEaqJT45QVuHpmpTPHxnDSd9MS
zCb+r+f8uzRlrfXkz+KdFLnYgrpDH5lw1nAfJdT7pWmUBuC0Em8J6iEd3HcnPW/3
g7juVedr3XfE3RC7wzMtAcPvCvZ2x7yXZCuEkhHftA846EA1Veebk6+GIrgQkaHi
iNRoLCJ0mlkMDsEbMUrcxEj1fxP8B0TT+QMRaDdeGhvaX3LeTHJXpW7hBE3fafbO
ci0xIOP/FjDwoiHi36Qml1pD933dJtf5gT2EuiRJmVuFfSgsuyvkn7VTabNHcthA
IK4YsIv4ud8lRcYF1BbI+zxef6en3aXZrqpHdyp3rEvQWdMXFus=
=I7dn
—–END PGP SIGNATURE—–

AutorVlatka Misic
Cert idNCERT-REF-2020-05-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa OpenShift Service Mesh

Otkriven je sigurnosni nedostatak u programskom paketu OpenShift Service Mesh za operacijski sustav RHEL. Otkriveni nedostatak potencijalnim napadačima omogućuje izazivanje...

Close