![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| Security Advisories (RSS) UNIX and Linux Security Advisories Via RSS News |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| USN-628-1: PHP vulnerabilities | iBot | Security Advisories (RSS) | 0 | 07-23-2008 04:10 PM |
| S-332: Vulnerabilities in DNS | iBot | Security Advisories (RSS) | 0 | 07-17-2008 01:40 PM |
| S-254: Vulnerabilities in GDI | iBot | Security Advisories (RSS) | 0 | 04-09-2008 06:00 PM |
| USN-571-1: X.org vulnerabilities | iBot | Security Advisories (RSS) | 0 | 01-18-2008 02:50 AM |
| S-100: GNU Tar Vulnerabilities | iBot | Security Advisories (RSS) | 0 | 01-03-2008 07:20 PM |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|||||
|
USN-641-1: Racoon vulnerabilities
Referenced CVEs:
CVE-2008-3651, CVE-2008-3652 Description: =========================================================== Ubuntu Security Notice USN-641-1 September 09, 2008ipsec-tools vulnerabilitiesCVE-2008-3651, CVE-2008-3652===========================================================A security issue affects the following Ubuntu releases:Ubuntu 6.06 LTSUbuntu 7.04Ubuntu 7.10Ubuntu 8.04 LTSThis advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 6.06 LTS: racoon 1:0.6.5-4ubuntu1.2Ubuntu 7.04: racoon 1:0.6.6-3ubuntu3.1Ubuntu 7.10: racoon 1:0.6.6-3.1ubuntu3.1Ubuntu 8.04 LTS: racoon 1:0.6.7-1.1ubuntu1.1In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:It was discovered that there were multiple ways to leak memory duringthe IKE negotiation when handling certain packets. If a remote attackersent repeated malicious requests, the "racoon" key exchange server couldallocate large amounts of memory, possibly leading to a denial of service. More... |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|