Home
Home
    • Blog
    • Clinic
    • Contact
    • Download
    • Video
    • Login

Poll

Favourite console text editor in Ubuntu:

LXer -- Linux and Open Source News

  • Use Linux to Scan Unusable Windows Drives for Viruses
  • SCO vs. Linux: From the Court of Appeals to the Supreme Court
  • Current Ubuntu 10.04 Review
  • How to compile the Linux kernel
  • Essential guide to picking an open source operating system
more

Linux Today

  • Leading Edge? Bleeding Edge? Be careful!
  • One Year Later: What Do You Think of Linux.com?
  • Vacuum Tube Radio Hat
  • A System Monitoring Tool Primer
  • Linux coolness: Linux Cooler, Linux serves you beer
more

Linux Insider

  • Android Has Enough Class for Opera
more

USN-785-1: ipsec-tools vulnerabilities

Submitted by k4tz on Wed, 06/10/2009 - 11:47
  • Linux World
  • Security
  • Ubuntu

===========================================================

Ubuntu Security Notice USN-785-1                                               June 09, 2009

ipsec-tools vulnerabilities

CVE-2009-1574, CVE-2009-1632 ===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

Ubuntu 8.04 LTS

Ubuntu 8.10

Ubuntu 9.04

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 6.06 LTS:

racoon 1:0.6.5-4ubuntu1.3

Ubuntu 8.04 LTS:

racoon 1:0.6.7-1.1ubuntu1.2

Ubuntu 8.10:

racoon 1:0.7-2.1ubuntu1.8.10.1

Ubuntu 9.04:

racoon 1:0.7-2.1ubuntu1.9.04.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

It was discovered that ipsec-tools did not properly handle certain fragmented packets. A remote attacker could send specially crafted packets to the server and cause a denial of service. (CVE-2009-1574)

It was discovered that ipsec-tools did not properly handle memory usage when verifying certificate signatures or processing nat-traversal keep-alive messages. A remote attacker could send specially crafted packets to the server and exhaust available memory, leading to a denial of service. (CVE-2009-1632)

 

Source: http://www.ubuntu.com/usn/USN-785-1

  • Add new comment

Recent blog posts

  • Configure ThinkPad laptop trackpoint on Ubuntu
  • How to make WPA connection in Ubuntu on demand
  • Review: Sabily 9.10 - Linux Ubuntu for Muslims
  • How to Install 64bit flash on Ubuntu
  • How to get Wireless LAN (Broadcom) on Acer Aspire 4720Z working with Ubuntu 9.10
  • Quick loot at Ubuntu 10.04 Lucid Lynx Alpha 3
  • System testing and benchmarking under Ubuntu 9.10
  • How to PXE booting Ubuntu Installer
  • How to Install Debian onto your Nexus One using Ubuntu
  • (Re) Install a Linux Kernel
more

Linux World

  • Microsoft's Internet Driving Licence: stupid, unworkable and unenforceable
  • Making a videoloop with Kino and Audacity
  • So is ChromeOS a desktop winner? I think not
  • Firefogg: Transcoding videos to open web standards with Mozilla Firefox
  • The Morevna Project: Anime with Synfig and Blender
Archive Syndicate content

Recent comments

  • Re
    9 weeks 6 days ago
  • Re
    9 weeks 6 days ago
  • Re
    10 weeks 6 days ago
  • Re
    11 weeks 2 days ago
  • Re
    12 weeks 8 hours ago
  • Re
    12 weeks 11 hours ago
  • Re
    12 weeks 1 day ago
  • iwl3945
    13 weeks 6 days ago
  • HomeBank
    26 weeks 6 hours ago
  • KMyMoney and direct connect to banks
    30 weeks 1 day ago
All contents copyright © 2008, Dhuha Net. All rights reserved
Ubuntudoctor® is a member of the Dhuha Network. Privacy Policy
RoopleTheme