KAME Racoon IDE Daemon X.509 Improper Certificate Verification Vulnerability
BID:10546
Info
KAME Racoon IDE Daemon X.509 Improper Certificate Verification Vulnerability
| Bugtraq ID: | 10546 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0607 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2004 12:00AM |
| Updated: | Feb 16 2007 07:37PM |
| Credit: | This issue was reported by Thomas Walpuski <[email protected]>. |
| Vulnerable: |
SGI Advanced Linux Environment 3.0 SCO Unixware 7.1.4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 KAME Racoon 20040503 KAME Racoon 20040407b KAME Racoon 20040405 KAME Racoon 20030711 KAME Racoon IPsec-Tools IPsec-Tools 0.3.2 IPsec-Tools IPsec-Tools 0.3.1 IPsec-Tools IPsec-Tools 0.3 rc5 IPsec-Tools IPsec-Tools 0.3 rc4 IPsec-Tools IPsec-Tools 0.3 rc3 IPsec-Tools IPsec-Tools 0.3 rc2 IPsec-Tools IPsec-Tools 0.3 rc1 IPsec-Tools IPsec-Tools 0.3 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.2.8 |
| Not Vulnerable: |
IPsec-Tools IPsec-Tools 0.3.3 |
Discussion
KAME Racoon IDE Daemon X.509 Improper Certificate Verification Vulnerability
Racoon improperly validates X.509 certificates when negotiating IPSec connections.
When checking certificate validity, Racoon ignores many errors from OpenSSL and grants access to invalid certificates.
When ignoring these errors, Racoon allows improper certificates to be used when authenticating connections.
This vulnerability could allow attackers to forge certificates and potentially gain access to IPSec VPNs. This would also effectively make all certificates permanent.
It is unknown which versions of Racoon are vulnerable at this time.
Racoon improperly validates X.509 certificates when negotiating IPSec connections.
When checking certificate validity, Racoon ignores many errors from OpenSSL and grants access to invalid certificates.
When ignoring these errors, Racoon allows improper certificates to be used when authenticating connections.
This vulnerability could allow attackers to forge certificates and potentially gain access to IPSec VPNs. This would also effectively make all certificates permanent.
It is unknown which versions of Racoon are vulnerable at this time.
Exploit / POC
KAME Racoon IDE Daemon X.509 Improper Certificate Verification Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
KAME Racoon IDE Daemon X.509 Improper Certificate Verification Vulnerability
Solution:
Reportedly, this issue has been fixed in the Linux port of Racoon distributed with IPsec-tools.
Please see the referenced advisories for more information.
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X Server 10.3.4
Apple Mac OS X 10.3.4
Apple Mac OS X Server 10.3.5
Apple Mac OS X 10.3.5
SCO Unixware 7.1.4
Solution:
Reportedly, this issue has been fixed in the Linux port of Racoon distributed with IPsec-tools.
Please see the referenced advisories for more information.
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-09-07JagClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04717&plat form=osx&method=sa/SecUpd2004-09-07JagClient.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecUpdSrvr2004-09-07Jag.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04716&plat form=osx&method=sa/SecUpdSrvr2004-09-07Jag.dmg
Apple Mac OS X Server 10.3.4
-
Apple SecUpdSrvr2004-09-07PanL.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04713&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanL.dmg
Apple Mac OS X 10.3.4
-
Apple SecUpd2004-09-07PanClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04712&plat form=osx&method=sa/SecUpd2004-09-07PanClient.dmg
Apple Mac OS X Server 10.3.5
-
Apple SecUpdSrvr2004-09-07PanM.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04714&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanM.dmg
Apple Mac OS X 10.3.5
-
Apple SecUpd2004-09-07PanMClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04715&plat form=osx&method=sa/SecUpd2004-09-07PanMClient.dmg
SCO Unixware 7.1.4
-
SCO erg712650.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/erg712650.pkg.Z -
SCO SCOSA-2005.10
UnixWare 7.1.4
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10
References
KAME Racoon IDE Daemon X.509 Improper Certificate Verification Vulnerability
References:
References:
- RHSA-2004:308-06 - Updated ipsec-tools package (RedHat)
- Vendor Homepage (KAME Project)
- authentication bug in KAME's racoon (Thomas Walpuski
) - Re: authentication bug in KAME's racoon (Michal Ludvig
)