Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE Linux Enterprise 11 Upgrades: Important OpenVPN Remote Shutdown Risk

suse
Calendar Grey June 21, 2017
Dist Suse Esm H88
Essential patch released for OpenVPN to tackle significant vulnerabilities on SUSE Linux Enterprise platforms.
An update that fixes one vulnerability is now available

Summary

This update for openvpn fixes the following issues: - It was possible to trigger an assertion by sending a malformed IPv6 packet. That issue could have been abused to remotely shutdown an openvpn server or client, if IPv6 and --mssfix were enabled and if the IPv6 networks used inside the VPN were known. [bsc#1044947, CVE-2017-7508] Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-openvpn-13166=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-openvpn-13166=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-openvpn-13166=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-openvpn-13166=1

References

#1044947

Cross- CVE-2017-7508

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2017-7508.html

https://bugzilla.suse.com/1044947

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1642-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here