Bug 26613 - libreswan new security issue CVE-2020-1763
Summary: libreswan new security issue CVE-2020-1763
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-05-12 16:11 CEST by David Walser
Modified: 2020-05-15 17:49 CEST (History)
5 users (show)

See Also:
Source RPM: libreswan-3.31-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-05-12 16:11:37 CEST
RedHat has issued an advisory today (May 12):
https://access.redhat.com/errata/RHSA-2020:2070

The issue is fixed upstream in 3.32:
https://libreswan.org/security/CVE-2020-1763/CVE-2020-1763.txt

Mageia 7 is also affected.
David Walser 2020-05-12 16:12:02 CEST

Status comment: (none) => Fixed upstream in 3.32
Whiteboard: (none) => MGA7TOO

Comment 1 David Walser 2020-05-12 16:52:28 CEST
Updated packages uploaded by Stig-Ørjan.

Advisory:
========================

Updated libreswan packages fix security vulnerability:

An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan.
An unauthenticated attacker could use this flaw to crash libreswan by sending
specially-crafted IKEv1 Informational Exchange packets. The daemon respawns
after the crash (CVE-2020-1763).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1763
https://libreswan.org/security/CVE-2020-1763/CVE-2020-1763.txt
https://access.redhat.com/errata/RHSA-2020:2070
========================

Updated packages in core/updates_testing:
========================
libreswan-3.32-1.mga7

from libreswan-3.32-1.mga7.src.rpm

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7
CC: (none) => smelror
Status comment: Fixed upstream in 3.32 => (none)
Assignee: smelror => qa-bugs

Comment 2 Herman Viaene 2020-05-13 16:32:04 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
Ref to bug 25065 and not noticing any ill effects on this laptop and its access to my LAN, OK'ing.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 3 Thomas Andrews 2020-05-15 00:53:19 CEST
Validating. Advisory in Comment 1.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2020-05-15 16:41:30 CEST

CC: (none) => tmb
Keywords: (none) => advisory

Comment 4 Mageia Robot 2020-05-15 17:49:40 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0215.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.