Home
Home
    • Blog
    • Clinic
    • Contact
    • Download
    • Video
    • Login

Poll

Favourite console text editor in Ubuntu:

LXer -- Linux and Open Source News

  • Humanity Icon Theme Updated To Match The New Ubuntu Branding
  • Wolvix linux - A linux distro based on Slackware with a graphic installation mode
  • HP Deskjet D2680 Review
  • Shuttleworth heir opens up on Ubuntu biz
  • Testing The Different Ubuntu 10.04 Kernels
more

Linux Today

  • The Microsoft Elephant in the Open Source Room
  • How To Harden PHP5 With Suhosin On CentOS 5.4
  • Seven Firefox Plug-ins That Improve Online Privacy
  • Bash History: Display Date And Time For Each Command
  • Leading Edge? Bleeding Edge? Be careful!
more

Linux Insider

  • Android Has Enough Class for Opera
more

USN-785-1: ipsec-tools vulnerabilities

Submitted by k4tz on Wed, 06/10/2009 - 11:47
  • Linux World
  • Security
  • Ubuntu

===========================================================

Ubuntu Security Notice USN-785-1                                               June 09, 2009

ipsec-tools vulnerabilities

CVE-2009-1574, CVE-2009-1632 ===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

Ubuntu 8.04 LTS

Ubuntu 8.10

Ubuntu 9.04

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 6.06 LTS:

racoon 1:0.6.5-4ubuntu1.3

Ubuntu 8.04 LTS:

racoon 1:0.6.7-1.1ubuntu1.2

Ubuntu 8.10:

racoon 1:0.7-2.1ubuntu1.8.10.1

Ubuntu 9.04:

racoon 1:0.7-2.1ubuntu1.9.04.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

It was discovered that ipsec-tools did not properly handle certain fragmented packets. A remote attacker could send specially crafted packets to the server and cause a denial of service. (CVE-2009-1574)

It was discovered that ipsec-tools did not properly handle memory usage when verifying certificate signatures or processing nat-traversal keep-alive messages. A remote attacker could send specially crafted packets to the server and exhaust available memory, leading to a denial of service. (CVE-2009-1632)

 

Source: http://www.ubuntu.com/usn/USN-785-1

  • Add new comment

Recent blog posts

  • Configure ThinkPad laptop trackpoint on Ubuntu
  • How to make WPA connection in Ubuntu on demand
  • Review: Sabily 9.10 - Linux Ubuntu for Muslims
  • How to Install 64bit flash on Ubuntu
  • How to get Wireless LAN (Broadcom) on Acer Aspire 4720Z working with Ubuntu 9.10
  • Quick loot at Ubuntu 10.04 Lucid Lynx Alpha 3
  • System testing and benchmarking under Ubuntu 9.10
  • How to PXE booting Ubuntu Installer
  • How to Install Debian onto your Nexus One using Ubuntu
  • (Re) Install a Linux Kernel
more

Linux World

  • Microsoft's Internet Driving Licence: stupid, unworkable and unenforceable
  • Making a videoloop with Kino and Audacity
  • So is ChromeOS a desktop winner? I think not
  • Firefogg: Transcoding videos to open web standards with Mozilla Firefox
  • The Morevna Project: Anime with Synfig and Blender
Archive Syndicate content

Recent comments

  • Re
    10 weeks 24 min ago
  • Re
    10 weeks 2 hours ago
  • Re
    10 weeks 6 days ago
  • Re
    11 weeks 3 days ago
  • Re
    12 weeks 1 day ago
  • Re
    12 weeks 1 day ago
  • Re
    12 weeks 2 days ago
  • iwl3945
    13 weeks 6 days ago
  • HomeBank
    26 weeks 23 hours ago
  • KMyMoney and direct connect to banks
    30 weeks 2 days ago
All contents copyright © 2008, Dhuha Net. All rights reserved
Ubuntudoctor® is a member of the Dhuha Network. Privacy Policy
RoopleTheme