Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2004:027: ipsec-tools


Vulnerability Assessment Details

MDKSA-2004:027: ipsec-tools

Vulnerability Assessment Summary
Check for the version of the ipsec-tools package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2004:027 (ipsec-tools).


A very serious security flaw was discovered by Ralf Spenneberg in racoon, the
IKE daemon of the KAME-tools. Racoon does not very the RSA signature during
phase one of a connection using either main or aggressive mode. Only the
certificate of the client is verified, the certificate is not used to verify the
client's signature.
All versions of ipsec-tools prior to 0.2.5 and 0.3rc5 are vulnerable to this
issue. The provided package updates ipsec-tools to 0.2.5.


Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:027
Network Security Threat Level: High

Networks Security ID: 10072

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors

DELL POWEREDGE R430 SERVER E5-2637V3 3.5GHZ 128GB 3 X 146GB H730
$4149.0
DELL POWEREDGE R430 SERVER E5-2637V3 3.5GHZ 128GB 3 X 146GB H730 pictureDELL POWEREDGE R730XD SERVER 24 BAY E5-2695V4 2.1GHZ 16GB 6 X 1.2TB 10K 12G H730
$5819.0
DELL POWEREDGE R730XD SERVER 24 BAY E5-2695V4 2.1GHZ 16GB 6 X 1.2TB 10K 12G H730 pictureDELL POWEREDGE R430 SERVER E5-2637V4 3.5GHZ 16GB 2133MHZ 3TB SAS H330
$2379.0
DELL POWEREDGE R430 SERVER E5-2637V4 3.5GHZ 16GB 2133MHZ 3TB SAS H330 pictureDELL POWEREDGE R820 SERVER 8B TWO E5-4603 2.0GHZ 128GB 5 X 250GB SATA H710P
$3219.0
DELL POWEREDGE R820 SERVER 8B TWO E5-4603 2.0GHZ 128GB 5 X 250GB SATA H710P picture


Discussions

No Discussions have been posted on this vulnerability.