Re: [OpenWrt-Devel] (CVE-2014-2338) authentication bypass vulnerability in strongSwan needs patching

2014-07-07 Thread John Crispin
i stopped bb-builder2 and pointed it at AA instead of BB. i will update strongswan, openssl and gnutls during the day. sorry for the delay, the old AA builders HDD died half way through the build 2 weeks ago and i was busy with BB and simply forgot. sorry for the delay On 06/07/2014 17:41,

Re: [OpenWrt-Devel] (CVE-2014-2338) authentication bypass vulnerability in strongSwan needs patching

2014-07-06 Thread Mirko Parthey
Am Sonntag, 06.07.14, 00:00 +0200 schrieb Noel Kuntze: I am once again inquiring about this vulnerabity. The strongSwan version in the repository for the 12.09 version of OpenWRT is still not patched and Mr. Fietkau does not respond to any emails. I wrote him one on 2014-06-08 and one on

Re: [OpenWrt-Devel] (CVE-2014-2338) authentication bypass vulnerability in strongSwan needs patching

2014-07-06 Thread Noel Kuntze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello Mirko, So fixes or new versions with fixes will only be backported, if there is a complete rebuilt scheduled for the release? Regards, Noel Kuntze GPG Key id: 0x63EC6658 Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658 Am

Re: [OpenWrt-Devel] (CVE-2014-2338) authentication bypass vulnerability in strongSwan needs patching

2014-07-05 Thread Noel Kuntze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello, I am once again inquiring about this vulnerabity. The strongSwan version in the repository for the 12.09 version of OpenWRT is still not patched and Mr. Fietkau does not respond to any emails. I wrote him one on 2014-06-08 and one on

Re: [OpenWrt-Devel] (CVE-2014-2338) authentication bypass vulnerability in strongSwan needs patching

2014-04-15 Thread Felix Fietkau
On 2014-04-15 00:33, Noel Kuntze wrote: Hello list, An authentication bypass vulnerability has been revealed by the strongSwan team. All versions of strongSwan since 4.0.7 are affected. All affected packages need to be patched. The patches for the different version can be gotten from

[OpenWrt-Devel] (CVE-2014-2338) authentication bypass vulnerability in strongSwan needs patching

2014-04-14 Thread Noel Kuntze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello list, An authentication bypass vulnerability has been revealed by the strongSwan team. All versions of strongSwan since 4.0.7 are affected. All affected packages need to be patched. The patches for the different version can be gotten from