Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Multiple vulnerabilites in vendor IKE implementations, including Cisco,
From: Chris <serlin () engsoc org>
Date: Thu, 18 Dec 2003 16:13:21 -0500


This is in response to the mail posted by Thor Lancelot Simon. The original mail is available at http://www.securityfocus.com/archive/1/347351 in which Thor has listed two issues. Documented below is Cisco's response to them.

Issue #1: Cisco addressed this issue as part of CSCdw87717 wherein the Cert Domain Name verification feature was implemented. This issue has been documented under the Cisco security advisory
http://www.cisco.com/warp/public/707/vpnclient-multiple2-vuln-pub.shtml.

I've looked through the literature and the software (4.0 rel) for the past week, I haven't been able to find anything related to this. I've had several people brighter than I look into this, they also weren't able to find any sort of fix. we may very well may have missed it, but is it possible this feature went missing in 4.0?

Thanks,
Chris


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]