Openswan IKE Traffic Denial Of Service Vulnerabilities
BID:15416
Info
Openswan IKE Traffic Denial Of Service Vulnerabilities
| Bugtraq ID: | 15416 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-3671 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2005 12:00AM |
| Updated: | May 10 2006 02:59AM |
| Credit: | Discovery is credited to the vendor. |
| Vulnerable: |
SuSE Linux Enterprise Server 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Fedora Core4 Redhat Fedora Core3 Openswan Openswan 2.4 Openswan Openswan 2.3.1 Openswan Openswan 2.3 Openswan Openswan 2.2 Openswan Openswan 2.1.6 Openswan Openswan 2.1.5 Openswan Openswan 2.1.4 Openswan Openswan 2.1.2 Openswan Openswan 2.1.1 Gentoo Linux Astaro Security Linux 4.0 28 |
| Not Vulnerable: |
Openswan Openswan 2.4.4 Openswan Openswan 2.4.2 Astaro Security Linux 4.0 29 |
Discussion
Openswan IKE Traffic Denial Of Service Vulnerabilities
Openswan is prone to multiple denial-of-service vulnerabilities in their ISAKMP implementation. Only attackers with access to the pre-shared key may exploit these issues, and only when the affected IKE daemon is configured to use aggressive mode.
These issues were discovered with the PROTOS ISAKMP Test Suite and are related to the handling of malformed IKEv1 traffic.
The vulnerabilities are believed to affect Openswan 2.x releases prior to 2.4.2.
Openswan is prone to multiple denial-of-service vulnerabilities in their ISAKMP implementation. Only attackers with access to the pre-shared key may exploit these issues, and only when the affected IKE daemon is configured to use aggressive mode.
These issues were discovered with the PROTOS ISAKMP Test Suite and are related to the handling of malformed IKEv1 traffic.
The vulnerabilities are believed to affect Openswan 2.x releases prior to 2.4.2.
Exploit / POC
Openswan IKE Traffic Denial Of Service Vulnerabilities
These issues can be reproduced using the PROTOS ISAKMP Test Suite.
These issues can be reproduced using the PROTOS ISAKMP Test Suite.
Solution / Fix
Openswan IKE Traffic Denial Of Service Vulnerabilities
Solution:
The vendor has released Openswan 2.4.2 to address the issues.
Please see the referenced advisories for further information.
Openswan Openswan 2.1.1
Openswan Openswan 2.1.2
Openswan Openswan 2.1.4
Openswan Openswan 2.1.5
Openswan Openswan 2.1.6
Openswan Openswan 2.2
Openswan Openswan 2.3
Openswan Openswan 2.3.1
Openswan Openswan 2.4
Solution:
The vendor has released Openswan 2.4.2 to address the issues.
Please see the referenced advisories for further information.
Openswan Openswan 2.1.1
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz
Openswan Openswan 2.1.2
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz
Openswan Openswan 2.1.4
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz
Openswan Openswan 2.1.5
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz -
RedHat Fedora openswan-2.4.4-0.FC3.1.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora openswan-doc-2.4.4-0.FC3.1.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora openswan-2.4.4-0.FC3.1.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora openswan-2.4.4-0.FC3.1.x86_64.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora openswan-doc-2.4.4-0.FC3.1.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora openswan-doc-2.4.4-0.FC3.1.x86_64.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
Openswan Openswan 2.1.6
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz
Openswan Openswan 2.2
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz -
SuSE openswan-2.2.0-12.4.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/openswan-2.2.0-12 .4.i586.rpm -
SuSE openswan-2.2.0-12.4.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/openswan-2.2.0- 12.4.x86_64.rpm -
SuSE openswan-2.2.0-8.4.i586.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/openswan-2.2.0-8. 4.i586.rpm -
SuSE openswan-2.2.0-8.4.x86_64.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/openswan-2.2.0- 8.4.x86_64.rpm
Openswan Openswan 2.3
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz
Openswan Openswan 2.3.1
-
RedHat Fedora openswan-2.4.4-1.0.FC4.1.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora openswan-2.4.4-1.0.FC4.1.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora openswan-2.4.4-1.0.FC4.1.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora openswan-doc-2.4.4-1.0.FC4.1.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
Openswan Openswan 2.4
-
Openswan openswan-2.4.2.tar.gz
http://www.openswan.org/download/openswan-2.4.2.tar.gz -
SuSE ipsec-tools-0.5-5.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/ipsec-tools-0.5 -5.2.x86_64.rpm -
SuSE openswan-2.4.4-1.1.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/openswan-2.4.4-1 .1.i586.rpm -
SuSE openswan-2.4.4-1.1.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/openswan-2.4.4-1. 1.ppc.rpm -
SuSE openswan-2.4.4-1.1.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/openswan-2.4.4 -1.1.x86_64.rpm
References
Openswan IKE Traffic Denial Of Service Vulnerabilities
References:
References:
- Multiple Vulnerability Issues in Implementations of ISAKMP Protocol (NISCC)
- Openswan Homepage (Openswan)
- Openswan response to NISCC Vulnerability Advisory 273756/NISCC/ISAKMP (Openswan)
- Up2Date 4.029 (Astaro)
- Re: [ GLSA 200512-04 ] Openswan, IPsec-Tools: Vulnerabilities in ISAK MP Protoco (Paul Wouters
)