Security update for ipsec-tools

SUSE Security Update: Security update for ipsec-tools
Announcement ID: SUSE-SU-2015:1367-1
Rating: moderate
References: #931989 #939810
Affected Products:
  • SUSE Linux Enterprise Server for VMWare 11-SP3
  • SUSE Linux Enterprise Server 11-SP4
  • SUSE Linux Enterprise Server 11-SP3
  • SUSE Linux Enterprise Debuginfo 11-SP3

  • An update that solves one vulnerability and has one errata is now available.

    Description:

    ipsec-tools was updated to fix one security issue and a bug.

    This security issue was fixed:

    - CVE-2015-4047: racoon/gssapi.c in ipsec-tools allowed remote attackers
    to cause a denial of service (NULL pointer dereference and IKE daemon
    crash) via a series of crafted UDP requests (bsc#931989).

    Due to a packaging error, the racoonf.conf config file was symlinked to
    /usr/share/doc/packages/ipsec-tools/examples/racoon/samples/racoon.conf
    on some processor platforms, edits might have happened only in this
    example file.

    Before upgrading, please check if /etc/racoon/racoon.conf is a symlink to
    this example file and backup the content. (bsc#939810)

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Server for VMWare 11-SP3:
      zypper in -t patch slessp3-ipsec-tools-12024=1
    • SUSE Linux Enterprise Server 11-SP4:
      zypper in -t patch slessp4-ipsec-tools-12024=1
    • SUSE Linux Enterprise Server 11-SP3:
      zypper in -t patch slessp3-ipsec-tools-12024=1
    • SUSE Linux Enterprise Debuginfo 11-SP3:
      zypper in -t patch dbgsp3-ipsec-tools-12024=1

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Server for VMWare 11-SP3 (i586 x86_64):
      • ipsec-tools-0.7.3-1.13.1
    • SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64):
      • ipsec-tools-0.7.3-1.13.1
    • SUSE Linux Enterprise Server 11-SP3 (i586 ia64 ppc64 s390x x86_64):
      • ipsec-tools-0.7.3-1.13.1
    • SUSE Linux Enterprise Debuginfo 11-SP3 (i586 ia64 ppc64 s390x x86_64):
      • ipsec-tools-debuginfo-0.7.3-1.13.1
      • ipsec-tools-debugsource-0.7.3-1.13.1

    References: