NI3
11-08-2003, 11:04 AM
TITLE:
OpenBSD ISAKMPd Multiple Security Issues
SECUNIA ADVISORY ID:
SA10168
VERIFY ADVISORY:
[Only registered and activated users can see links]
CRITICAL:
Less critical
IMPACT:
Manipulation of data, Exposure of sensitive information
WHERE:
From remote
OPERATING SYSTEM:
OpenBSD 3.x
DESCRIPTION:
Multiple security issues have been reported in OpenBSD ISAKMPd, which
potentially can be exploited by malicious people to gain knowledge of
sensitive information or delete SAs (Security Associations).
One problem is that some information isn't encrypted in "Quick Mode",
which is also the case for the last messages in "Main Mode". This
might disclose sensitive information.
Other problems when handling "Delete" messages allow for deletion of
IPSec and IKE SAs.
SOLUTION:
The vulnerabilities seem to be addressed in revision 1.62 in the CVS
repository.
[Only registered and activated users can see links]
[Only registered and activated users can see links]
REPORTED BY / CREDITS:
Thomas Walpuski
----------------------------------------------------------------------
OpenBSD ISAKMPd Multiple Security Issues
SECUNIA ADVISORY ID:
SA10168
VERIFY ADVISORY:
[Only registered and activated users can see links]
CRITICAL:
Less critical
IMPACT:
Manipulation of data, Exposure of sensitive information
WHERE:
From remote
OPERATING SYSTEM:
OpenBSD 3.x
DESCRIPTION:
Multiple security issues have been reported in OpenBSD ISAKMPd, which
potentially can be exploited by malicious people to gain knowledge of
sensitive information or delete SAs (Security Associations).
One problem is that some information isn't encrypted in "Quick Mode",
which is also the case for the last messages in "Main Mode". This
might disclose sensitive information.
Other problems when handling "Delete" messages allow for deletion of
IPSec and IKE SAs.
SOLUTION:
The vulnerabilities seem to be addressed in revision 1.62 in the CVS
repository.
[Only registered and activated users can see links]
[Only registered and activated users can see links]
REPORTED BY / CREDITS:
Thomas Walpuski
----------------------------------------------------------------------
