RHSA-2008:0849: Important: ipsec-tools security update
The ipsec-tools package is used in conjunction with the IPsec functionalityin the Linux kernel and includes racoon, an IKEv1 keying daemon.Two denial of service flaws were found in the ipsec-tools racoon daemon. Itwas possible for a remote attacker to cause the racoon daemon to consumeall available memory. (CVE-2008-3651, CVE-2008-3652)Users of ipsec-tools should upgrade to this updated package, which containsbackported patches that resolve these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0849?
The severity of RHSA-2008:0849 is classified as important due to the potential for denial of service attacks.
How do I fix RHSA-2008:0849?
To fix RHSA-2008:0849, users should upgrade the ipsec-tools package to version 0.6.5-9.el5_2.3 or 0.3.3-7.el4_7 as applicable.
What vulnerabilities are addressed in RHSA-2008:0849?
RHSA-2008:0849 addresses two denial of service vulnerabilities in the racoon daemon of the ipsec-tools package.
Which versions of ipsec-tools are affected by RHSA-2008:0849?
Versions up to 0.6.5-9.el5_2.3 for el5 and up to 0.3.3-7.el4_7 for el4 are affected by RHSA-2008:0849.
Can RHSA-2008:0849 be exploited remotely?
Yes, RHSA-2008:0849 can be exploited remotely by an attacker to cause a denial of service.