Date: Tue, 18 Oct 2016 13:19:26 -0600 From: Kurt Seifried <kseifried@...hat.com> To: oss-security <oss-security@...ts.openwall.com> Cc: Huzaifa Sidhpurwala <huzaifas@...hat.com>, CVE ID Requests <cve-assign@...re.org> Subject: Re: Re: CVE Request: IKEv1 protocol is vulnerable to DoS amplification attack On Tue, Jul 12, 2016 at 1:46 PM, Paul Wouters <pwouters@...hat.com> wrote: > > > I have tested openswan and strongswan and confirmed it contains the same > amplification that is inherent in being IKEv1 compliant. > > Neither implementation has applied the hardening that libreswan has > applied for this that was the original information that caused > CVE-2016-5361 to be issued for libreswan. > > I believe MITRE needs to fix the inconsistency in the issuance of > CVE-2016-5361, expand it to be about the IKEv1 protocol, and gather > the other vendor information and patches, or issue additional vendor > specific CVE's. I believe the first solution is better. > > Paul > So I had a chance to talk to Paul Basically: the RFC doesn't define a specific way to handle this, as such a CVE cannot be given to the RFC (currently CVEs will be given to RFCs/protocols that say "do something bad" like using weak encryption algorithms). As such it was left up to all the IKE implementations themselves to determine what to do with respect to retransmits. I think it's safe to say an amplification of 1:10 or more qualifies as a problem, I'm not sure what the exact amplification ratio to qualify for a CVE is (1:3, 1:7?) but I think 1:10 or more should definitely qualify. Thus a lot of other IKE implementations will be needing CVEs for this class of problem (as well as other protocols). -- Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 Red Hat Product Security contact: secalert@...hat.com
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.