CVE-2008-1198

The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:43

Type Values Removed Values Added
References () http://secunia.com/advisories/48045 - Broken Link () http://secunia.com/advisories/48045 - Broken Link
References () http://www.ernw.de/download/pskattack.pdf - Exploit () http://www.ernw.de/download/pskattack.pdf - Exploit
References () http://www.securitytracker.com/id?1019563 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id?1019563 - Third Party Advisory, VDB Entry
References () https://bugzilla.redhat.com/show_bug.cgi?id=435274 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=435274 - Issue Tracking
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/41053 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/41053 - VDB Entry

Information

Published : 2008-03-06 21:44

Updated : 2024-11-21 00:43


NVD link : CVE-2008-1198

Mitre link : CVE-2008-1198

CVE.ORG link : CVE-2008-1198


JSON object : View

Products Affected

redhat

  • enterprise_linux