Amazon Linux AMI : openswan (ALAS-2011-06)

This script is Copyright (C) 2013-2015 Tenable Network Security, Inc.

Synopsis :

The remote Amazon Linux AMI host is missing a security update.

Description :

When an ISAKMP message with an invalid KEY_LENGTH attribute is
received, the error handling function crashes on a NULL pointer
dereference. Openswan automatically restarts the pluto IKE daemon but
all ISAKMP state is lost. This vulnerability does NOT allow an
attacker access to the system. This can be used to launch a denial of
service attack by sending repeated IKE packets with the invalid key
length attribute.

See also :

Solution :

Run 'yum upgrade openswan' to upgrade your system.

Risk factor :

Medium / CVSS Base Score : 5.0

Family: Amazon Linux Local Security Checks

Nessus Plugin ID: 69565 ()

Bugtraq ID:

CVE ID: CVE-2011-3380

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now