|
|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:027: ipsec-tools Vulnerability Scan
Vulnerability Scan Summary Check for the version of the ipsec-tools package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:027 (ipsec-tools).
A very serious security flaw was discovered by Ralf Spenneberg in racoon, the
IKE daemon of the KAME-tools. Racoon does not very the RSA signature during
phase one of a connection using either main or aggressive mode. Only the
certificate of the client is verified, the certificate is not used to verify the
client's signature.
All versions of ipsec-tools prior to 0.2.5 and 0.3rc5 are vulnerable to this
issue. The provided package updates ipsec-tools to 0.2.5.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:027
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|