|
FreeS/WAN X.509 Patch Certificate Verification Vulnerability
Solution: Gentoo has released advisory GLSA 200406-20 to address this issue. Gentoo have advised the following: All FreeS/WAN 1.9x users should upgrade to the latest stable version: # emerge sync # emerge -pv "=net-misc/freeswan-1.99-r1" # emerge "=net-misc/freeswan-1.99-r1" All FreeS/WAN 2.x users should upgrade to the latest stable version: # emerge sync # emerge -pv ">=net-misc/freeswan-2.04-r1" # emerge ">=net-misc/freeswan-2.04-r1" All Openswan 1.x users should upgrade to the latest stable version: # emerge sync # emerge -pv "=net-misc/openswan-1.0.6_rc1" # emerge "=net-misc/openswan-1.0.6_rc1" All Openswan 2.x users should upgrade to the latest stable version: # emerge sync # emerge -pv ">=net-misc/openswan-2.1.4" # emerge ">=net-misc/openswan-2.1.4" All strongSwan users should upgrade to the latest stable version: # emerge sync # emerge -pv ">=net-misc/strongswan-2.1.3" # emerge ">=net-misc/strongswan-2.1.3" All Super-FreeS/WAN users should migrate to the latest stable version of Openswan. Note that Portage will force a move for Super-FreeS/WAN users to Openswan: # emerge sync # emerge -pv "=net-misc/openswan-1.0.6_rc1" # emerge "=net-misc/openswan-1.0.6_rc1" Mandrake has released an advisory (MDKSA-2004:070) to address this issue. Please see the referenced advisory for more information. |
|
Privacy Statement |