Amazon Linux AMI : openswan (ALAS-2011-06)

This script is Copyright (C) 2013-2015 Tenable Network Security, Inc.


Synopsis :

The remote Amazon Linux AMI host is missing a security update.

Description :

When an ISAKMP message with an invalid KEY_LENGTH attribute is
received, the error handling function crashes on a NULL pointer
dereference. Openswan automatically restarts the pluto IKE daemon but
all ISAKMP state is lost. This vulnerability does NOT allow an
attacker access to the system. This can be used to launch a denial of
service attack by sending repeated IKE packets with the invalid key
length attribute.

See also :

http://www.openswan.org/download/CVE-2011-3380/CVE-2011-3380.txt
https://alas.aws.amazon.com/ALAS-2011-6.html

Solution :

Run 'yum upgrade openswan' to upgrade your system.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)

Family: Amazon Linux Local Security Checks

Nessus Plugin ID: 69565 ()

Bugtraq ID:

CVE ID: CVE-2011-3380

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial