REDHAT-BUG-456660: Medium severity ipsec-tools vulnerability
ipsec-tools upstream released 0.7.1 including a fix for a memory leak in racoon daemon triggered by the invalid proposals, possibly resulting in a denial of service once daemon runs out of memory.
References: http://marc.info/?l=ipsec-tools-devel&m=121688914101709&w=2 http://bugs.gentoo.org/showbug.cgi?id=232831
Upstream patch: http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/proposal.c.diff?r1=1.15&r2=1.16&f=h http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/ChangeLog.diff?r1=1.169&r2=1.170&f=h
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-456660?
The severity of REDHAT-BUG-456660 is critical due to the potential denial of service caused by the memory leak.
How do I fix REDHAT-BUG-456660?
To fix REDHAT-BUG-456660, upgrade to ipsec-tools version 0.7.1 or later where the memory leak issue has been resolved.
What are the consequences of not addressing REDHAT-BUG-456660?
Failing to address REDHAT-BUG-456660 can lead to a denial of service as the racoon daemon runs out of memory.
Which applications are affected by REDHAT-BUG-456660?
The vulnerability REDHAT-BUG-456660 affects applications using the ipsec-tools package, particularly the racoon daemon.
Is there a workaround for REDHAT-BUG-456660?
Currently, there are no known workarounds for REDHAT-BUG-456660; the best resolution is to upgrade the software.