File _patchinfo of Package patchinfo.3365

<patchinfo incident="3365">
  <issue id="897512" tracker="bnc" />
  <issue id="897048" tracker="bnc" />
  <issue id="910491" tracker="bnc">CVE-2014-9221: DoS via payload with DH group 1025</issue>
  <issue id="CVE-2014-9221" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>mtomaschewski</packager>
  <description>
  This update fixes the following security issues:

- denial-of-service vulnerability, which can be triggered by an IKEv2 Key Exchange payload, that
  contains the Diffie-Hellman group 1025 (bsc#910491,CVE-2014-9221).
- Applied an upstream patch reverting to store algorithms in the
  registration order again as ordering them by identifier caused
  weaker algorithms to be proposed first by default (bsc#897512).

</description>
  <summary>Security update for strongswan</summary>
</patchinfo>
openSUSE Build Service is sponsored by