oss-sec mailing list archives
Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack
From: Paul Wouters <pwouters () redhat com>
Date: Mon, 13 Jun 2016 11:07:49 -0400
On 06/13/2016 10:40 AM, cve-assign () mitre org wrote:
Its not libreswan which is flawed, but its the protocol which they are trying to implement.which implement IKEv1 are flawed, since they follow this protocolMany protocols could be described as "flawed." The IKEv1 protocol amplification concern does not make it flawed in a way that would lead to a per-protocol CVE ID assignment. We are maintaining the CVE-2016-5361 ID assignment for the upstream announcement of "libreswan 3.16 vulnerable to DDOS attack. Please upgrade to 3.17" and accompanying upstream patch, as described in the http://www.openwall.com/lists/oss-security/2016/06/10/4 post.
<with upstream libreswan hat on> If you want us to keep honestly reporting security issues, I recommend you not single out single implementations over RFC compliant protocol flaws. I'm fine if you list the CVE with the 6 vulnerable implementations, then say libreswan has fixed it. I'm not okay with libreswan being listed as vulnerable and the other 5 vulnerable implementations not being listed. If you keep the CVE as-is, we will document it at libreswan.org/security/ as a mis-issued CVE entry. Related, I would _REALLY_ appreciate it if MITR talks to us before issuing CVE's for our software. We've been at this long before MITR, we respond within days, we are known to have coordinated CVE issues for IKE implementation issues across various implementations. You can contact us at security () libreswan org, PGP key available at the usual places. Paul
Current thread:
- CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Huzaifa Sidhpurwala (Jun 09)
- Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack cve-assign (Jun 10)
- Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Huzaifa Sidhpurwala (Jun 12)
- Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack cve-assign (Jun 13)
- Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Paul Wouters (Jun 13)
- Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Paul Wouters (Jun 14)
- Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Huzaifa Sidhpurwala (Jun 12)
- Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack cve-assign (Jun 10)