Bug 1050277 (CVE-2013-6466)
| Summary: | CVE-2013-6466 openswan: dereferencing missing IKEv2 payloads causes pluto daemon to restart | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Kurt Seifried <kseifried> | ||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
| Status: | CLOSED ERRATA | QA Contact: | |||||
| Severity: | medium | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | unspecified | CC: | amarecek, jkurik, kseifried, mkolaja, mrogers, nobody, pwouters, security-response-team | ||||
| Target Milestone: | --- | Keywords: | Security | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2016-06-10 20:13:47 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | 1050322, 1050325, 1050337, 1050340, 1058402 | ||||||
| Bug Blocks: | 1050315 | ||||||
| Attachments: |
|
||||||
|
Description
Kurt Seifried
2014-01-08 21:44:19 UTC
External References: https://libreswan.org/security/CVE-2013-6467/CVE-2013-6467.txt Created openswan tracking bugs for this issue: Affects: fedora-all [bug 1058402] we don't ship openswan in fedora anymore. The packages have been obsoleted by the libreswan packages. We cannot do any more fedora openswan packages. Note that openswan-2.6.40 did not properly fix this issue, as they did not use the backported libreswan patch we provided them. So while openswan 2.6.40 will get a new CVE number for this issue, our packages for errata RHSA-2014:0185 are not vulnerable. This issue has been addressed in following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Via RHSA-2014:0185 https://rhn.redhat.com/errata/RHSA-2014-0185.html A CVE for upstream openswan will be assigned soon, as this CVE was not fully fixed in the upstream release. The Red Hat packages, however, used the correct patch and thus fully fixed the issue. CVE-2014-2037 is assigned to openswan-2.6.41. And to confirm, our release from RHSA-2014:0185 is not vulnerable CVE-2014-2037 is assigned to openswan-2.6.40 Created attachment 867908 [details]
plutodebug=all log
|