From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-201309-02.xml | 61 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 glsa-201309-02.xml (limited to 'glsa-201309-02.xml') diff --git a/glsa-201309-02.xml b/glsa-201309-02.xml new file mode 100644 index 00000000..f12252c7 --- /dev/null +++ b/glsa-201309-02.xml @@ -0,0 +1,61 @@ + + + + + + strongSwan: Multiple vulnerabilities + Multiple vulnerabilities have been found in strongSwan, possibly + allowing remote attackers to authenticate as other users or cause a Denial + of Service condition. + + strongswan + September 01, 2013 + September 01, 2013: 1 + 468504 + 479396 + 483202 + remote + + + 5.1.0 + 5.1.0 + + + +

strongSwan is an IPSec implementation for Linux.

+
+ +

Multiple vulnerabilities have been discovered in strongSwan. Please + review the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could use ECDSA to authenticate as another user with + an invalid signature. Additionally, a remote attacker could send a + specially crafted request, possibly resulting in a Denial of Service. +

+
+ +

There is no known workaround at this time.

+
+ +

All strongSwan users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/strongswan-5.1.0" + + +
+ + CVE-2013-2054 + CVE-2013-2944 + CVE-2013-5018 + + + creffett + + + creffett + +
-- cgit v1.2.3-65-gdbad