OpenBSD ISAKMPD IPsec Replay Vulnerability
BID:19712
CVE-2006-4436 |Info
OpenBSD ISAKMPD IPsec Replay Vulnerability
| Bugtraq ID: | 19712 |
| Class: | Design Error |
| CVE: |
CVE-2006-4436 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2006 12:00AM |
| Updated: | Nov 08 2006 10:11PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
OpenBSD OpenBSD 3.9 OpenBSD OpenBSD 3.8 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
OpenBSD ISAKMPD IPsec Replay Vulnerability
OpenBSD's IPsec implementation is prone to remote replay attacks. This issue is due to the improper implementation of its replay window.
This issue allows remote attackers to replay IPsec traffic. The exact consequences of successful attacks depend on the nature of the traffic being replayed. This will likely affect only higher-level protocols such as UDP, since they don't provide their own anti-replay features.
OpenBSD's IPsec implementation is prone to remote replay attacks. This issue is due to the improper implementation of its replay window.
This issue allows remote attackers to replay IPsec traffic. The exact consequences of successful attacks depend on the nature of the traffic being replayed. This will likely affect only higher-level protocols such as UDP, since they don't provide their own anti-replay features.
Exploit / POC
OpenBSD ISAKMPD IPsec Replay Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
OpenBSD ISAKMPD IPsec Replay Vulnerability
Solution:
The vendor has released patches to address this issue.
Please see the referenced advisories for more information.
OpenBSD OpenBSD 3.8
OpenBSD OpenBSD 3.9
Debian Linux 3.1
Solution:
The vendor has released patches to address this issue.
Please see the referenced advisories for more information.
OpenBSD OpenBSD 3.8
-
OpenBSD 013_isakmpd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/013_isakmpd.patch
OpenBSD OpenBSD 3.9
-
OpenBSD 008_isakmpd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/008_isakmpd.patch
Debian Linux 3.1
-
Debian isakmpd_20041012-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_alpha.deb -
Debian isakmpd_20041012-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_amd64.deb -
Debian isakmpd_20041012-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_arm.deb -
Debian isakmpd_20041012-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_hppa.deb -
Debian isakmpd_20041012-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_i386.deb -
Debian isakmpd_20041012-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_ia64.deb -
Debian isakmpd_20041012-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_m68k.deb -
Debian isakmpd_20041012-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_mips.deb -
Debian isakmpd_20041012-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_mipsel.deb -
Debian isakmpd_20041012-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_powerpc.deb -
Debian isakmpd_20041012-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_s390.deb -
Debian isakmpd_20041012-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/isakmpd/isakmpd_2004101 2-1sarge1_sparc.deb
References
OpenBSD ISAKMPD IPsec Replay Vulnerability
References:
References:
- OpenBSD Errata Page (OpenBSD)
- OpenBSD Homepage (OpenBSD)
- OpenBSD Security Information (OpenBSD)