Openswan: Denial of service Multiple vulnerabilities in Openswan may create a Denial of Service condition. Openswan 2012-03-16 2012-03-16 372961 389097 local, remote 2.6.37 2.6.37

Openswan is an implementation of IPsec for Linux.

Two vulnerabilities have been found in Openswan:

A remote authenticated attacker or a local attacker may be able to cause a Denial of Service condition.

There is no known workaround at this time.

All Openswan users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/openswan-2.6.37"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since November 10, 2011. It is likely that your system is already no longer affected by this issue.

CVE-2011-2147 CVE-2011-4073 ackle ackle