TMCnet News
Mu Dynamics Remediates Open Source VPN Vulnerability in strongSwan IKEv2(Wireless News Via Acquire Media NewsEdge) Mu Dynamics, a company focusing on helping network operators and their vendors eliminate downtime through proactive service assurance, has discovered and helped remediate a dangerous 0-day vulnerability within strongSwan's IKEv2 implementation. strongSwan is an open source IPsec-based virtual private network (VPN) solution for the Linux operating system. IPsec-based VPNs secure corporate VoIP, email, web, IPTV and other IP-based services over public network infrastructures. According to the company, a precise sequence of complex events (the IKEv2 protocol) is required to establish VPN connectivity. strongSwan includes an Internet Key Exchange version 2 implementation (IKEv2) to authenticate users and establish session keys, enabling Internet Protocol (IP) traffic to be encrypted and/or digitally signed within IPsec-based VPNs. Mu Labs discovered that an unauthenticated anonymous attacker could crash a strongSwan-based VPN terminator or other IPsec device using only the very first IKEv2 packet. "The best defense against this 0-day vulnerability is to immediately upgrade to the patched version of strongSwan," said Thomas Maufer, Mu Dynamics' Director of Technical Marketing. "The Mu Labs development team appreciates strongSwan's extremely rapid response time in producing a fix to this serious bug in just one day." ((Comments on this story may be sent to [email protected])) ((Distributed on behalf of 10Meters via M2 Communications Ltd - http://www.m2.com)) ((10Meters - http://www.10meters.com)) Copyright ? 2008 Wireless News |
