MGASA-2019-0210

Source
https://advisories.mageia.org/MGASA-2019-0210.html
Import Source
https://advisories.mageia.org/MGASA-2019-0210.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0210
Related
Published
2019-07-21T18:17:27Z
Modified
2019-07-21T12:40:24Z
Summary
Updated libreswan packages fix security vulnerability
Details

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29 (CVE-2019-10155).

References
Credits

Affected packages

Mageia:7 / libreswan

Package

Name
libreswan
Purl
pkg:rpm/mageia/libreswan?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.29-1.1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / unbound

Package

Name
unbound
Purl
pkg:rpm/mageia/unbound?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-1.1.mga7

Ecosystem specific

{
    "section": "core"
}