Bug 174164

Summary: CVE-2005-3732 ipsec-tools IKE DoS
Product: [Fedora] Fedora Reporter: Mark J. Cox <mjc>
Component: ipsec-toolsAssignee: Harald Hoyer <harald>
Status: CLOSED RAWHIDE QA Contact:
Severity: low Docs Contact:
Priority: medium    
Version: 5CC: sundaram
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,public=20051120,reported=20051121,source=redhat
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-09-29 10:32:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Mark J. Cox 2005-11-25 12:36:07 UTC
Tracking for FC5test1

+++ This bug was initially created as a clone of Bug #173842 +++

ipsec-tools IKE DoS

There is a denial of service bug in racoon which can only be triggered
by having a very weak configuration.

More information is in the message posted to the ipsec-tools mailing 
list:
http://sourceforge.net/mailarchive/forum.php?thread_id=9017454&forum_id=32000

The patch is here:
http://cvs.sourceforge.net/viewcvs.py/ipsec-tools/ipsec-tools/src/racoon/isakmp_agg.c?r1=1.20.2.3&r2=1.20.2.4&diff_format=u


This issue also affects FC3

Comment 1 Rahul Sundaram 2006-02-20 11:09:54 UTC

These bugs are being closed since a large number of updates have been released
after the FC5 test1 and test2 releases. Kindly update your system by running yum
update as root user or try out the third and final test version of FC5 being
released in a short while and verify if the bugs are still present on the system
.Reopen or file new bug reports as appropriate after confirming the presence of
this issue. Thanks