Rapid7 Vulnerability & Exploit Database

RHSA-2004:308: ipsec-tools security update

Back to Search

RHSA-2004:308: ipsec-tools security update

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
12/06/2004
Created
07/25/2018
Added
10/28/2005
Modified
07/12/2017

Description

An updated ipsec-tools package that fixes verification of X.509 certificates in racoon is now available.

IPSEC uses strong cryptography to provide both authentication and encryption services. When configured to use X.509 certificates to authenticate remote hosts, ipsec-tools versions 0.3.3 and earlier will attempt to verify that host certificate, but will not abort the key exchange if verification fails. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0607 to this issue. Users of ipsec-tools should upgrade to this updated package which contains a backported security patch and is not vulnerable to this issue.

Solution(s)

  • redhat-upgrade-ipsec-tools

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;