SUSE-SU-2015:1367-1

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20151367-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1367-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:1367-1
Upstream
  • CVE-2015-4047
Related
Published
2015-08-06T10:04:53Z
Modified
2026-02-04T04:04:33Z
Summary
Security update for ipsec-tools
Details

ipsec-tools was updated to fix one security issue and a bug.

This security issue was fixed:

  • CVE-2015-4047: racoon/gssapi.c in ipsec-tools allowed remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests (bsc#931989).

Due to a packaging error, the racoonf.conf config file was symlinked to /usr/share/doc/packages/ipsec-tools/examples/racoon/samples/racoon.conf on some processor platforms, edits might have happened only in this example file.

Before upgrading, please check if /etc/racoon/racoon.conf is a symlink to this example file and backup the content. (bsc#939810)

References

Affected packages

SUSE:Linux Enterprise Server 11 SP3
ipsec-tools

Package

Name
ipsec-tools
Purl
pkg:rpm/suse/ipsec-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.3-1.13.1

Ecosystem specific

{
    "binaries":  [
        {
            "ipsec-tools":  "0.7.3-1.13.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1367-1.json"
SUSE:Linux Enterprise Server 11 SP3-TERADATA
ipsec-tools

Package

Name
ipsec-tools
Purl
pkg:rpm/suse/ipsec-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.3-1.13.1

Ecosystem specific

{
    "binaries":  [
        {
            "ipsec-tools":  "0.7.3-1.13.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1367-1.json"
SUSE:Linux Enterprise Server 11 SP4
ipsec-tools

Package

Name
ipsec-tools
Purl
pkg:rpm/suse/ipsec-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.3-1.13.1

Ecosystem specific

{
    "binaries":  [
        {
            "ipsec-tools":  "0.7.3-1.13.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1367-1.json"
SUSE:Linux Enterprise Server for SAP Applications 11 SP3
ipsec-tools

Package

Name
ipsec-tools
Purl
pkg:rpm/suse/ipsec-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.3-1.13.1

Ecosystem specific

{
    "binaries":  [
        {
            "ipsec-tools":  "0.7.3-1.13.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1367-1.json"
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
ipsec-tools

Package

Name
ipsec-tools
Purl
pkg:rpm/suse/ipsec-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.3-1.13.1

Ecosystem specific

{
    "binaries":  [
        {
            "ipsec-tools":  "0.7.3-1.13.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1367-1.json"