diff options
author | Nicolás Reynolds <fauno@parabola.nu> | 2013-05-24 14:07:18 -0300 |
---|---|---|
committer | Nicolás Reynolds <fauno@parabola.nu> | 2013-05-24 14:07:18 -0300 |
commit | 3bb2d69f78cc242bd1d314131e45a13dc6697bc2 (patch) | |
tree | 63be1b3f97dbe222ae6fb70b0cfd203db0e52341 /pcr/strongswan/CHANGELOG | |
parent | 8febad754f500027e10af865b0f9f0f5bbc38b3e (diff) |
IPSec implementations
Diffstat (limited to 'pcr/strongswan/CHANGELOG')
-rw-r--r-- | pcr/strongswan/CHANGELOG | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/pcr/strongswan/CHANGELOG b/pcr/strongswan/CHANGELOG new file mode 100644 index 000000000..a798a08c4 --- /dev/null +++ b/pcr/strongswan/CHANGELOG @@ -0,0 +1,20 @@ +strongswan-5.0.4 +---------------- + +- Fixed a security vulnerability in the openssl plugin which was reported by + Kevin Wojtysiak. The vulnerability has been registered as CVE-2013-2944. + Before the fix, if the openssl plugin's ECDSA signature verification was used, + due to a misinterpretation of the error code returned by the OpenSSL + ECDSA_verify() function, an empty or zeroed signature was accepted as a + legitimate one. + +- The handling of a couple of other non-security relevant openssl return codes + was fixed as well. + +- The tnc_ifmap plugin now publishes virtual IPv4 and IPv6 addresses via its + TCG TNC IF-MAP 2.1 interface. + +- The charon.initiator_only option causes charon to ignore IKE initiation + requests. + +- The openssl plugin can now use the openssl-fips library. |