ELSA-2023-3095

ELSA-2023-3095 - libreswan security and bug fix update

Type:SECURITY
Impact:MODERATE
Release Date:2023-05-24

Description


[4.9-2.0.1.2]
- Add libreswan-oracle.patch to detect Oracle Linux distro

[4.9-2.2]
- Update libreswan-4.9-2176248-authby-rsasig.patch

[4.9-2.1]
- Resolves: rhbz#2187647 authby=rsasig fails in FIPS policy

[4.9-2]
- Fix CVE-2023-23009: remote DoS via crafted TS payload with an
incorrect selector length (rhbz#2186127)


Related CVEs


CVE-2023-23009

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) libreswan-4.9-2.0.1.el8_8.2.src.rpm5707f2acbdcd894e2a4c0bae453fd767007448eb51aac2672395aa3e369c538e-ol8_aarch64_appstream
libreswan-4.9-2.0.1.el8_8.2.aarch64.rpmc374d9f04ccc763924f5f588b781c78413731ce8508ad6029967fccda087eb8b-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) libreswan-4.9-2.0.1.el8_8.2.src.rpm5707f2acbdcd894e2a4c0bae453fd767007448eb51aac2672395aa3e369c538e-ol8_x86_64_appstream
libreswan-4.9-2.0.1.el8_8.2.x86_64.rpmb31fbc6d99a8ff58afd161fe2aa964bfb9abc5b58fa1664cc4a97296463bbc85-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete