Summary
Ubuntu Update for Linux kernel vulnerabilities USN-641-1
Solution
Please Install the Updated Packages.
Insight
It was discovered that there were multiple ways to leak memory during the IKE negotiation when handling certain packets. If a remote attacker sent repeated malicious requests, the "
racoon"
key exchange server could
allocate large amounts of memory, possibly leading to a denial of service.
Affected
ipsec-tools vulnerabilities on Ubuntu 6.06 LTS ,
Ubuntu 7.04 ,
Ubuntu 7.10 ,
Ubuntu 8.04 LTS
Severity
Classification
-
CVE CVE-2008-3651, CVE-2008-3652 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities