ELSA-2023-3095

ELSA-2023-3095 - libreswan security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2023-05-24

Description


[4.9-2.0.1.2]
- Add libreswan-oracle.patch to detect Oracle Linux distro

[4.9-2.2]
- Update libreswan-4.9-2176248-authby-rsasig.patch

[4.9-2.1]
- Resolves: rhbz#2187647 authby=rsasig fails in FIPS policy

[4.9-2]
- Fix CVE-2023-23009: remote DoS via crafted TS payload with an
incorrect selector length (rhbz#2186127)


Related CVEs


CVE-2023-23009

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) libreswan-4.9-2.0.1.el8_8.2.src.rpm9589abbd43b6f4a5a503e7b8c754c9cb-
libreswan-4.9-2.0.1.el8_8.2.aarch64.rpm43d365825a4821eb375368e95b7d3c02-
Oracle Linux 8 (x86_64) libreswan-4.9-2.0.1.el8_8.2.src.rpm9589abbd43b6f4a5a503e7b8c754c9cb-
libreswan-4.9-2.0.1.el8_8.2.x86_64.rpma620d2c9cc69a1d8554f5023e15af534-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete