LWN.net Logo

initscripts: network traffic sniffing

Package(s):initscripts CVE #(s):CVE-2008-1198
Created:February 21, 2012 Updated:March 22, 2012
Description: From the Red Hat advisory:

With the default IPsec (Internet Protocol Security) ifup script configuration, the racoon IKE key management daemon used aggressive IKE mode instead of main IKE mode. This resulted in the preshared key (PSK) hash being sent unencrypted, which could make it easier for an attacker able to sniff network traffic to obtain the plain text PSK from a transmitted hash.

Alerts:
Red Hat RHSA-2012:0312-03 2012-02-21
Oracle ELSA-2012-0312 2012-03-07
Scientific Linux SL-init-20120321 2012-03-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds