Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 25: 2017-0639fb1490 Critical: OpenVPN Security Update

fedora
Calendar Grey June 23, 2017
Dist Fedora Esm H88
OpenVPN 2.4.3 security patch launched for Fedora 25 tackling severe flaws and enhancing restart capabilities.
Updates to the latest upstream OpenVPN 2.4.3, containing security updates for CVE-2017-7508, CVE-2017-7520 and CVE-2017-7521

Summary

OpenVPN is a robust and highly flexible tunneling application that uses all

of the encryption, authentication, and certification features of the

OpenSSL library to securely tunnel IP networks over a single UDP or TCP

port. It can use the Marcus Franz Xaver Johannes Oberhumers LZO library

for compression.

Updates to the latest upstream OpenVPN 2.4.3, containing security updates for

CVE-2017-7508, CVE-2017-7520 and CVE-2017-7521. This update also re-enables

automatic restart of OpenVPN on the next updates. For this update, the restart

needs to be done manually.

[ 1 ] Bug #1463643 - CVE-2017-7508 CVE-2017-7520 CVE-2017-7521 CVE-2017-7522 openvpn: Multiple security issues fixed in OpenVPN 2.4.3 and 2.3.17 [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1463643

[ 2 ] Bug #1463647 - openvpn-2.4.3 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1463647

su -c 'dnf upgrade openvpn' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 2.4.3
Release: 1.fc25
URL:
Summary: A full-featured SSL VPN solution

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here