SUSE-SU-2015:1367-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1367-1
SUSE-SU-2015:1367-1
Summary: Security update for ipsec-tools
Details: ipsec-tools was updated to fix one security issue and a bug. This security issue was fixed: - CVE-2015-4047: racoon/gssapi.c in ipsec-tools allowed remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests (bsc#931989). Due to a packaging error, the racoonf.conf config file was symlinked to /usr/share/doc/packages/ipsec-tools/examples/racoon/samples/racoon.conf on some processor platforms, edits might have happened only in this example file. Before upgrading, please check if /etc/racoon/racoon.conf is a symlink to this example file and backup the content. (bsc#939810)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151367-1/, https://bugzilla.suse.com/931989, https://bugzilla.suse.com/939810, https://www.suse.com/security/cve/CVE-2015-4047
Affected packages
Package
Name: ipsec-tools
Purl: pkg:rpm/suse/ipsec-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
