Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

SUSE: 2014:1694-1 Important: Openvpn Denial Of Service Fix

suse
Calendar Grey December 23, 2014
Dist Suse Esm H88
Critical patch released for openvpn tackling a denial of service vulnerability identified in SUSE platforms.
An update that fixes one vulnerability is now available

Summary

A remote denial of service attack against openvpn was fixed, where a authenticated client cloud stop the server by triggering a server-side ASSERT (CVE-2014-8104), Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2014-120 - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2014-120 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 12 (ppc64le s390x x86_64): openvpn-2.3.2-11.1 openvpn-auth-pam-plugin-2.3.2-11.1 openvpn-auth-pam-plugin-debuginfo-2.3.2-11.1 openvpn-debuginfo-2.3.2-11.1 openvpn-debugsource-2.3.2-11.1

References

#907764

Cross- CVE-2014-8104

Affected Products:

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2014-8104.html

https://bugzilla.suse.com/show_bug.cgi?id=907764

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1694-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here