Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51110
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2004:308
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2004:308.

IPSEC uses strong cryptography to provide both authentication and
encryption services.

When configured to use X.509 certificates to authenticate remote hosts,
ipsec-tools versions 0.3.3 and earlier will attempt to verify that host
certificate, but will not abort the key exchange if verification fails.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-0607 to this issue.

Users of ipsec-tools should upgrade to this updated package which contains
a backported security patch and is not vulnerable to this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2004-308.html
http://marc.theaimsgroup.com/?l=bugtraq&m=108726102304507

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: BugTraq ID: 10546
Common Vulnerability Exposure (CVE) ID: CVE-2004-0607
http://www.securityfocus.com/bid/10546
Bugtraq: 20040614 authentication bug in KAME's racoon (Google Search)
http://marc.info/?l=bugtraq&m=108726102304507&w=2
Bugtraq: 20040615 Re: authentication bug in KAME's racoon (Google Search)
http://marc.info/?l=bugtraq&m=108731967126033&w=2
http://security.gentoo.org/glsa/glsa-200406-17.xml
http://www.osvdb.org/7113
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9163
http://www.redhat.com/support/errata/RHSA-2004-308.html
SCO Security Bulletin: SCOSA-2005.10
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
http://securitytracker.com/id?1010495
http://secunia.com/advisories/11863
http://secunia.com/advisories/11877
XForce ISS Database: racoon-eaycheckx509cert-auth-bypass(16414)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16414
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.