Revision Date: | 2004-07-29 | Version: | 502 |
Title: | RHSA-2004:308: ipsec-tools security update (Important) |
Description: | IPSEC uses strong cryptography to provide both authentication and encryption services.
When configured to use X.509 certificates to authenticate remote hosts, ipsec-tools versions 0.3.3 and earlier will attempt to verify that host certificate, but will not abort the key exchange if verification fails. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0607 to this issue.
Users of ipsec-tools should upgrade to this updated package which contains a backported security patch and is not vulnerable to this issue.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2004-0607 RHSA-2004:308-01
|
Platform(s): | Red Hat Enterprise Linux 3
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux 3 is installed AND ipsec-tools is earlier than 0:0.2.5-0.5
AND ipsec-tools is signed with Red Hat master key
|