DSA-4684-1 libreswan -- security update

Related Vulnerabilities: CVE-2020-1763  

Stephan Zeisberg discovered that the libreswan IPsec implementation could be forced into a crash/restart via a malformed IKEv1 Informational Exchange packet, resulting in denial of service. For the stable distribution (buster), this problem has been fixed in version 3.27-6+deb10u1. We recommend that you upgrade your libreswan packages. For the detailed security status of libreswan please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libreswan

Debian Security Advisory

DSA-4684-1 libreswan -- security update

Date Reported:
13 May 2020
Affected Packages:
libreswan
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 960458.
In Mitre's CVE dictionary: CVE-2020-1763.
More information:

Stephan Zeisberg discovered that the libreswan IPsec implementation could be forced into a crash/restart via a malformed IKEv1 Informational Exchange packet, resulting in denial of service.

For the stable distribution (buster), this problem has been fixed in version 3.27-6+deb10u1.

We recommend that you upgrade your libreswan packages.

For the detailed security status of libreswan please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libreswan