<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>112568</bug_id>
          
          <creation_ts>2005-11-14 18:30 0000</creation_ts>
          <short_desc>net-misc/openswan Multiple Vulnerability Issues in Implementation of ISAKMP Protocol</short_desc>
          <delta_ts>2005-12-12 06:55:02 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.niscc.gov.uk/niscc/docs/br-20051114-01013.html</bug_file_loc>
          <status_whiteboard>B3 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>pfeifer@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>mlspamcb@noci.xs4all.nl</cc>
    
    <cc>pfeifer@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-14 18:30:39 0000</bug_when>
            <thetext>New bug affecting at least one ipsec product offered by Gentoo

Reproducible: Always
Steps to Reproduce:
1.
2.
3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-14 18:33:48 0000</bug_when>
            <thetext>openswan-1.x is not vulnerable.
openswan-2.4.1 and earlier are.
I am testing an openswan-2.4.2 ebuild and will upload shortly.

Reference:
http://lists.openswan.org/pipermail/dev/2005-November/001121.html</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-14 18:35:03 0000</bug_when>
            <thetext>strongswan is not vulnerable.

Reference:
http://lists.strongswan.org/pipermail/users/2005-November/001191.html
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-14 19:16:02 0000</bug_when>
            <thetext>ok, openswan-2.4.2 is in portage. need to get 2.4.2 stable on amd64 (i have
hardware) then i will remove 2.2.0 and mark 2.4.2 stable on x86 and amd64.
anyone on the amd64 team want to test as well?

all revisions of openswan are ~ppc so leaving that way. however, getting ppc
team member to test would be great as my ppc hardware is no longer running linux.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-14 19:35:47 0000</bug_when>
            <thetext>ok, just for those who may test, i am working on an openswan-2.4.3 ebuild as
there was an assert found when using a PSK+ID in aggressive mode. Just got the
info from kenb with xelerence and downloaded the new tarball. i&apos;ll put a note
here when it is in portage.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-14 20:13:36 0000</bug_when>
            <thetext>openswan-2.4.3 is in portage.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-11-14 22:42:08 0000</bug_when>
            <thetext>Arches please test and mark stable. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-11-15 00:46:41 0000</bug_when>
            <thetext>Readding amd64. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mlspamcb@noci.xs4all.nl</who>
            <bug_when>2005-11-15 15:59:13 0000</bug_when>
            <thetext>Is there is reason the KLIPS engine cannot be selected for 2.6? 
 
(IMHO) The KLIPS engine has some advantages when builing netfilter rules. 
 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2005-11-15 22:01:32 0000</bug_when>
            <thetext>Hopefully I&apos;m not alone here, but could someone tell me how I can test this on
x86 to make sure it is not broken?  Upstream&apos;s wiki appears to be down.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-16 10:08:06 0000</bug_when>
            <thetext>Mark - i have already tested some on x86, but there are a number of scenarios.
You can look here: http://gentoo-wiki.com/HOWTO_OpenSwan_2.6_kernel for some info.

If you need further help, just find me on IRC.

Jay</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-17 11:18:32 0000</bug_when>
            <thetext>*sigh*... openswan-2.4.4 is on it&apos;s way (as per kenb from xelerance). it has
more ddos fixes. i will post an update once it is released and i test/commit it
to portage.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-11-20 04:19:50 0000</bug_when>
            <thetext>Back to upstream waiting for 2.4.4 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-25 04:34:26 0000</bug_when>
            <thetext>2005-11-18 : Xelerance has released Openswan 2.4.4 that fixes the secound
vulnerability found by the NISCC Advisory 3756/NISCC/ISAKMP.

See http://www.openswan.org/niscc2/ and bump.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-27 23:51:37 0000</bug_when>
            <thetext>2.4.4 is now in portage. Unless we get a huge bug report, I plan on marking this
stable on x86/amd64 and getting rid of 2.2.0 in 24 hours.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-29 02:36:10 0000</bug_when>
            <thetext>maintainer / x86 / amd64 teams: please mark 2.4.4 stable (if stable :) )</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pfeifer@gentoo.org</who>
            <bug_when>2005-11-29 06:50:23 0000</bug_when>
            <thetext>openswan-2.4.4 is now marked stable on x86 and amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-29 07:00:08 0000</bug_when>
            <thetext>Ready for GLSA vote. I tend to vote yes, due to the original issue (3DES crafted
packet with invalid keylength) rather than the additional lame ones (DoS if PSK
known and aggressive mode enabled, already vulnerable to MiM anyway)...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2005-12-02 04:20:47 0000</bug_when>
            <thetext>I tend to say yes, too</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2005-12-02 04:36:11 0000</bug_when>
            <thetext>Yes please issue a GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2005-12-02 04:40:02 0000</bug_when>
            <thetext>k, this is ready for GLSA then.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-12-12 06:55:02 0000</bug_when>
            <thetext>GLSA 200512-04</thetext>
          </long_desc>
      
    </bug>

</bugzilla>