oss-sec mailing list archives
Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack
From: Paul Wouters <pwouters () redhat com>
Date: Tue, 12 Jul 2016 22:46:04 +0300
On 06/14/2016 05:34 PM, Paul Wouters wrote:
On 06/13/2016 10:40 AM, cve-assign () mitre org wrote:Its not libreswan which is flawed, but its the protocol which they are trying to implement.which implement IKEv1 are flawed, since they follow this protocolMany protocols could be described as "flawed." The IKEv1 protocol amplification concern does not make it flawed in a way that would lead to a per-protocol CVE ID assignment.Then you should pull the CVE-2016-5361 which deals with retransmission amplification in IKEv1 We are maintaining theCVE-2016-5361 ID assignment for the upstream announcement of "libreswan 3.16 vulnerable to DDOS attack. Please upgrade to 3.17"That statement on the libreswan website is clearly referring to CVE-2016-3071 not CVE-2016-5361. andaccompanying upstream patch, as described in the http://www.openwall.com/lists/oss-security/2016/06/10/4 post.Which again clearly refers to CVE-2016-5361 and not CVE-2016-3071 So again, please fix CVE-2016-5361 or drop it.
I have tested openswan and strongswan and confirmed it contains the same amplification that is inherent in being IKEv1 compliant. Neither implementation has applied the hardening that libreswan has applied for this that was the original information that caused CVE-2016-5361 to be issued for libreswan. I believe MITRE needs to fix the inconsistency in the issuance of CVE-2016-5361, expand it to be about the IKEv1 protocol, and gather the other vendor information and patches, or issue additional vendor specific CVE's. I believe the first solution is better. Paul
Current thread:
- Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Seaman, Chad (Jul 07)
- Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Paul Wouters (Jul 08)
- <Possible follow-ups>
- Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack Paul Wouters (Jul 12)