Subject: Re: widespread IKE bugs
To: Jed Davis <jdev@panix.com>
From: Daniel Carosone <dan@geek.com.au>
List: tech-security
Date: 11/16/2005 07:24:57
--IrSfZTInSE10h3HO
Content-Type: text/plain; charset=us-ascii
Content-Disposition: attachment
Content-Transfer-Encoding: quoted-printable

On Tue, Nov 15, 2005 at 03:10:50PM -0500, Jed Davis wrote:
> Dries Schellekens <gwyllion@ulyssis.org> writes:
>=20
> > OpenBSD has audited their IKE parsing code early 2004 and thus is not
> > vunerable:
>
> However, that sentence can also be read as meaning that the audit
> necessarily implies the code's safety, and it is this which caused
> several people to take issue with it --- including me, though I came
> in late enough to see the response to Thor's comment first.

Me too.

Does anyone have test results against NetBSD, please?  Remember that
we're interested in both KAME and ipsec-tools, because of code on
release branches.

--
Dan.

--IrSfZTInSE10h3HO
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (NetBSD)

iD8DBQFDekQZEAVxvV4N66cRAslUAKDLZXwqx+VE+im/PFrjPPf4clkQ9gCg4GZ0
WjKlPz5V2BkkLC3UdzP46MA=
=6ZqN
-----END PGP SIGNATURE-----

--IrSfZTInSE10h3HO--