Format: 1.7 Date: Tue, 17 Jan 2012 16:53:31 +0100 Source: openswan Binary: openswan openswan-modules-source linux-patch-openswan Architecture: sparc_translations sparc Version: 1:2.4.9+dfsg-1ubuntu0.1 Distribution: hardy Urgency: low Maintainer: Ubuntu/sparc Build Daemon Changed-By: Harald Jenny Description: linux-patch-openswan - IPSEC Linux kernel support for Openswan openswan - IPSEC utilities for Openswan openswan-modules-source - IPSEC kernel modules source for Openswan Launchpad-Bugs-Fixed: 917754 Changes: openswan (1:2.4.9+dfsg-1ubuntu0.1) hardy-security; urgency=low . * SECURITY UPDATE: symlink attack through predictable filenames in /tmp - debian/patches/02-fix-unsecure-tmp-file.dpatch: change programs/livetest/livetest.in to use mktemp for temporary file creation. Patch taken from Debian openswan 1:2.4.12+dfsg-1.3 package. - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496374 * SECURITY UPDATE: denial of service attack via malicious Dead Peer Detection packet - debian/patches/03-CVE-2009-0790.dpatch: adjust programs/pluto/demux.c to check for a possbile NULL value. Patch taken from Debian openswan 1:2.4.12+dfsg-1.3+lenny1 package. - CVE-2009-0790 * SECURITY UPDATE: denial of service attack via specially crafted X.509 certificate - debian/patches/04-CVE-2009-2185.dpatch: create include/oswtime.h and modify programs/pluto/asn1.c as well as lib/libopenswan/optionsfrom.c to do proper checks on certificate objects length. Patch taken from Debian openswan 1:2.4.12+dfsg-1.3+lenny2 package. - CVE-2009-2185 * SECURITY UPDATE: denial of service attack via deliberately interrupted IPSec connection attempt - debian/patches/05-2.4.9-CVE-2011-4073.dpatch: change programs/pluto/ikev1_continuations.h and programs/pluto/ikev1_quick.c to check for vanished ISAKMP SA in Quick Mode negotiation. Patch taken from Debian openswan 1:2.4.12+dfsg-1.3+lenny3 package and slightly modified. - CVE-2011-4073 (LP: #917754) Files: c0073c59293f43492f5e2fd85dd68373 36521 raw-translations - openswan_2.4.9+dfsg-1ubuntu0.1_sparc_translations.tar.gz 5b56ee3d51372c0fdd724e3ded5b50c6 1740028 net optional openswan_2.4.9+dfsg-1ubuntu0.1_sparc.deb Original-Maintainer: Rene Mayrhofer