|
|
| |
|
| |
initscripts: network traffic sniffing
| Package(s): | initscripts |
CVE #(s): | CVE-2008-1198
|
| Created: | February 21, 2012 |
Updated: | March 22, 2012 |
| Description: |
From the Red Hat advisory:
With the default IPsec (Internet Protocol Security) ifup script
configuration, the racoon IKE key management daemon used aggressive IKE
mode instead of main IKE mode. This resulted in the preshared key (PSK)
hash being sent unencrypted, which could make it easier for an attacker
able to sniff network traffic to obtain the plain text PSK from a
transmitted hash. |
| Alerts: |
|
( Log in to post comments)
|
|
|