-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4684-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 13, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libreswan CVE ID : CVE-2020-1763 Debian Bug : 960458 Stephan Zeisberg discovered that the libreswan IPsec implementation could be forced into a crash/restart via a malformed IKEv1 Informational Exchange packet, resulting in denial of service. For the stable distribution (buster), this problem has been fixed in version 3.27-6+deb10u1. We recommend that you upgrade your libreswan packages. For the detailed security status of libreswan please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libreswan Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl68RM9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RWCw//Te2J/Kk2Jz6o2Ld51VnQAi18+aNRBCd17Qrm8I/uzrzWDExH+5A4s3fk 9NVKUd0Qce/1ceNihmAosr6sGM6EAK04dTX8uKa8024pl/X1hQuxUYUQkoVlHD8r LBgaQzassxmnEjTkkuU5oX60Zzn6AKVoRmNJalHN7b5ribRwKRMwxHrra/NtM0gi 5FUnFqR47Z071I7oM0ib2by+eIWyvXs+Yhrz7iQPtjSvWRbZyxr9hYgUr/GQAygK 7GccDnnaNiGYtzotEOwGZrOi4PsMAIjW7ha5yl+/f69Dk22vQ53gvb5UrVBNrcXm RKcflpLYHMujjGnGQ3b7lW6Gqdyf0grq3gekq9CEaqJT45QVuHpmpTPHxnDSd9MS zCb+r+f8uzRlrfXkz+KdFLnYgrpDH5lw1nAfJdT7pWmUBuC0Em8J6iEd3HcnPW/3 g7juVedr3XfE3RC7wzMtAcPvCvZ2x7yXZCuEkhHftA846EA1Veebk6+GIrgQkaHi iNRoLCJ0mlkMDsEbMUrcxEj1fxP8B0TT+QMRaDdeGhvaX3LeTHJXpW7hBE3fafbO ci0xIOP/FjDwoiHi36Qml1pD933dJtf5gT2EuiRJmVuFfSgsuyvkn7VTabNHcthA IK4YsIv4ud8lRcYF1BbI+zxef6en3aXZrqpHdyp3rEvQWdMXFus= =I7dn -----END PGP SIGNATURE-----