Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Debian: DSA-3084-1 Moderate: OpenVPN Control Packet Crash

debian
Calendar Grey December 1, 2014
Scroller Debian
A verified user might destabilize an OpenVPN server by transmitting an improperly formatted control packet. Mitigate this issue by implementing the necessary updates.
Dragana Damjanovic discovered that an authenticated client could crash an OpenVPN server by sending a control packet containing less than four bytes as payload

Summary

Dragana Damjanovic discovered that an authenticated client could crash
an OpenVPN server by sending a control packet containing less than
four bytes as payload.

For the stable distribution (wheezy), this problem has been fixed in
version 2.2.1-8+deb7u3.

For the unstable distribution (sid), this problem has been fixed in
version 2.3.4-5.

We recommend that you upgrade your openvpn packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: openvpn
CVE ID: CVE-2014-8104

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.