Chapter 1. Package Updates
194
1.166.2. RHSA-2009:0402: Important security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0402
1372
Updated openswan packages that fix various security issues are now available for Red Hat Enterprise
Linux 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
Openswan is a free implementation of Internet Protocol Security (IPsec) and Internet Key Exchange
(IKE). IPsec uses strong cryptography to provide both authentication and encryption services. These
services allow you to build secure tunnels through untrusted networks. Everything passing through the
untrusted network is encrypted by the IPsec gateway machine, and decrypted by the gateway at the
other end of the tunnel. The resulting tunnel is a virtual private network (VPN).
Gerd v. Egidy discovered a flaw in the Dead Peer Detection (DPD) in Openswan's pluto IKE daemon.
A remote attacker could use a malicious DPD packet to crash the pluto daemon. (
CVE-2009-0790
1373
)
It was discovered that Openswan's livetest script created temporary files in an insecure manner. A
local attacker could use this flaw to overwrite arbitrary files owned by the user running the script.
(
CVE-2008-4190
1374
)
Note: The livetest script is an incomplete feature and was not automatically executed by any other
script distributed with Openswan, or intended to be used at all, as was documented in its man page.
In these updated packages, the script only prints an informative message and exits immediately when
run.
All users of openswan are advised to upgrade to these updated packages, which contain backported
patches to correct these issues. After installing this update, the ipsec service will be restarted
automatically.
1.166.3. RHEA-2009:1350: bug fix update
An updated openswan package that resolves several issues and provides FIPS-1402-2 compliance is
now available.
Openswan is a free implementation of IPsec & IKE for Linux. IPsec is the Internet Protocol Security
and uses strong cryptography to provide both authentication and encryption services. These services
allow you to build secure tunnels through untrusted networks. Everything passing through the
untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other
end of the tunnel. The resulting tunnel is a virtual private network or VPN.
This package contains the daemons and userland tools for setting up Openswan. It optionally also
builds the Openswan KLIPS IPsec stack that is an alternative for the NETKEY/XFRM IPsec stack that
exists in the default Linux kernel.
1373
https://www.redhat.com/security/data/cve/CVE-2009-0790.html
1374
https://www.redhat.com/security/data/cve/CVE-2008-4190.html
Содержание ENTERPRISE 5.4 RELEASE NOTES
Страница 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Страница 18: ...xviii ...
Страница 306: ...288 ...
Страница 464: ...446 ...
Страница 466: ...448 ...