Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2014:1605-1 Important: OpenVPN Denial of Service Security Fix

suse
Calendar Grey December 9, 2014
Dist Suse Esm H88
Crucial SUSE Security Patch tackles severe OpenVPN Denial of Service vulnerability, safeguarding system stability.
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

This update fixes a critical denial of service vulnerability in OpenVPN: * CVE-2014-8104: Critical denial of service vulnerability in OpenVPN servers that can be triggered by authenticated attackers. Also an incompatibility with OpenVPN and OpenSSL in FIPS mode has been fixed. (bnc#895882) Security Issues: * CVE-2014-8104 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP3 for VMware: zypper in -t patch slessp3-openvpn-10061 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-openvpn-10061 - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-openvpn-10061

References

#895882 #907764

Cross- CVE-2014-8104

Affected Products:

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-8104.html

https://bugzilla.suse.com/show_bug.cgi?id=895882

https://bugzilla.suse.com/show_bug.cgi?id=907764

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1605-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here