lp://staging/~zulcss/ubuntu/intrepid/ipsec-tools/src-374185

Created by Chuck Short and last modified
Get this branch:
bzr branch lp://staging/~zulcss/ubuntu/intrepid/ipsec-tools/src-374185
Only Chuck Short can upload to this branch. If you are Chuck Short please log in for upload directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Chuck Short
Status:
Development

Recent revisions

20. By Chuck Short

src/racoon/ipsec_doi.c: Patched to fix segfault when using
ipv6 addresses in sainfo section of racoon.conf. Thanks to
Fredrik Ljunggren. (LP: #374185)

19. By Marc Deslauriers

* SECURITY UPDATE: denial of service via fragmented packets without a
  payload.
  - src/racoon/isakmp_frag.c: validate size of payload data.
  - http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/isakmp_frag.c.diff?r1=1.4&r2=1.4.6.1&f=h
  - CVE-2009-1574
* SECURITY UPDATE: denial of service via multiple memory leaks.
  - src/racoon/crypto_openssl.c: call X509_free().
  - src/racoon/nattraversal.c: add new natt_keepalive_delete() function
    that also frees ka->src and ka->dst.
  - http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/crypto_openssl.c.diff?r1=1.11.6.4&r2=1.11.6.5&f=u
  - http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/nattraversal.c.diff?r1=1.6&r2=1.6.6.1&f=u
  - CVE-2009-1632

18. By Mathias Gug

* Merge from debian unstable, remaining changes:
  - debian/control:
    - Set Ubuntu maintainer address.
    - Depend on lsb-base.
  - debian/ipsec-tools.setkey.init:
    - LSB init script.
* Dropped:
  - debian/ipsec-tools.setkey.init:
    - restart method: stop then start.
    - Use {} instead of () in usage (bash_completion).
  - debian/racoon.init:
    - Create /var/run/racoon.
    - Use {} instead of () in usage (bash_completion).
* Bug fixed by this merge:
    - fix XAuth with U-FQDN (LP: #234166).
* Enable build with hardened options:
  - src/libipsec/policy_token.c: don't check return code of fwrite.
  - src/setkey/setkey.c: stop scanning stdin if fgets fails.

17. By Mathias Gug

* Merge from debian unstable, remaining changes:
  - debian/control:
    - Set Ubuntu maintainer address.
    - Depend on lsb-base.
  - debian/ipsec-tools.setkey.init:
    - LSB init script.
    - restart method: stop then start.
    - Use {} instead of () in usage (bash_completion).
  - debian/racoon.init:
    - Create /var/run/racoon.
    - Use {} instead of () in usage (bash_completion).
* Dropped:
  - src/racoon/isakmp_inf.c: upstream fix for unecrypted ISAKMP packets.
  - src/racoon/grabmyaddr.c: Define IFA_RTA and #include <linux/if_addr.h>.

16. By Patrick Hetu

fix racoon.init to work with bash_completion (LP: #88153)

15. By Matthias Klose

Fix compilation errors with GCC-4.2.

14. By Kees Cook

* Merge from debian unstable, remaining changes:
  - src/racoon/isakmp_inf.c: upstream fix for unecrypted ISAKMP packets.
  - src/racoon/grabmyaddr.c: Define IFA_RTA and #include <linux/if_addr.h>.
  - debian/control: Set Ubuntu maintainer address.
  - LSB init script.
  - debian/racoon.init: Create /var/run/racoon.

13. By Kees Cook

* SECURITY UPDATE: remote ipsec tunnel disruption.
* src/racoon/isakmp_inf.c: upstream fix for unecrypted ISAKMP packets
  causing tunnels to be disconnected.
* References
  CVE-2007-1841

12. By Matthias Klose

* Rebuild for changes in the amd64 toolchain.
* Set Ubuntu maintainer address.

11. By Martin Pitt

* Merge from debian unstable.
  - LSB init script.
  - debian/racoon.init: Create /var/run/racoon.
* src/racoon/grabmyaddr.c: Define IFA_RTA and #include <linux/if_addr.h>.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar RepositoryFormatKnitPack6RichRoot (bzr 1.9)
Stacked on:
lp://staging/ubuntu/karmic/ipsec-tools
This branch contains Public information 
Everyone can see this information.

Subscribers