Re: FreeBSD Security Advisory FreeBSD-SA-06:11.ipsec




Hello!

On Wed, 22 Mar 2006, FreeBSD Security Advisories wrote:
II. Problem Description

IPsec provides an anti-replay service which when enabled prevents an attacker
from successfully executing a replay attack. This is done through the
verification of sequence numbers. A programming error in the fast_ipsec(4)
implementation results in the sequence number associated with a Security
Association not being updated, allowing packets to unconditionally pass
sequence number verification checks.

III. Impact

An attacker able to to intercept IPSec packets can replay them. If higher
level protocols which do not provide any protection against packet replays
(e.g., UDP) are used, this may have a variety of effects.

As far as I understood, only systems which use "options FAST_IPSEC" are affected by this issue. Is it true? If so, wouldn't be wise to stress this
fact in the advisory?


Sincerely, Dmitry
--
Atlantis ISP, System Administrator
e-mail: dmitry@xxxxxxxxxxxxxx
nic-hdl: LYNX-RIPE
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Species diversity through time
    ... Replay the tape ... sort of arms race between an attacker and a defender of some type. ... I tend to think that selection is more important than variation, and Gould was wrong about replaying the tape of life and ending up with totally different life forms. ...
    (talk.origins)
  • Re: Species diversity through time
    ... Replay the tape ... of evolution, he said. ... sort of arms race between an attacker and a defender of some type. ...
    (talk.origins)
  • Re: Unauthorized workstation connections to network...
    ... NTLM doesn't enter into IPsec as a threat at all. ... Kerberos might, but I have only seen academic references to attacks, nothing ... With IPSec, an attacker still has ...
    (microsoft.public.windows.server.security)
  • Re: context negotiation performance problem
    ... >>re-use of a transmitted authenticator by an attacker. ... >>If your protocol or threat model is such that replay attacks are not ... >>processes would probably deal better with the fsync calls. ...
    (comp.protocols.kerberos)
  • Re: Unauthorized workstation connections to network...
    ... I'm not sure where NTLM came from... ... NTLM doesn't enter into IPsec as a threat at all. ... >> fast decision that states that only those machines that can authenticate ... >>> added under their desk or the DoS when that attacker clones their MAC ...
    (microsoft.public.windows.server.security)