Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian: DSA-3084-1 Moderate: OpenVPN Control Packet Crash

debian
Calendar Grey December 1, 2014
Debian Logo
A verified user might destabilize an OpenVPN server by transmitting an improperly formatted control packet. Mitigate this issue by implementing the necessary updates.
Dragana Damjanovic discovered that an authenticated client could crash an OpenVPN server by sending a control packet containing less than four bytes as payload

Summary

Dragana Damjanovic discovered that an authenticated client could crash
an OpenVPN server by sending a control packet containing less than
four bytes as payload.

For the stable distribution (wheezy), this problem has been fixed in
version 2.2.1-8+deb7u3.

For the unstable distribution (sid), this problem has been fixed in
version 2.3.4-5.

We recommend that you upgrade your openvpn packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: openvpn
CVE ID: CVE-2014-8104

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here