Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: Important Security Issues in OpenVPN Addressed in 2017:2838-1

suse
Calendar Grey October 24, 2017
Dist Suse Esm H88
This important software update addresses vulnerabilities in sshd, targeting memory leaks and exploit risks. Protect your system!
An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now a...

Summary

This update for openvpn fixes the following security issues: - CVE-2017-12166: OpenVPN was vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution. (bsc#1060877). - CVE-2016-6329: Now show which ciphers should no longer be used in openvpn --show-ciphers to avoid the SWEET32 attack (bsc#995374) - CVE-2017-7478: OpenVPN was vulnerable to unauthenticated Denial of Service of server via received large control packet. (bsc#1038709) - CVE-2017-7479: OpenVPN was vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker. (bsc#1038711) - Some other hardening fixes have also been applied (bsc#1038713) Patch Instructions: To install this SUSE Security Update use YaST online_update.

References

#1038709 #1038711 #1038713 #1060877 #995374

Cross- CVE-2016-6329 CVE-2017-12166 CVE-2017-7478

CVE-2017-7479

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2016-6329.html

https://www.suse.com/security/cve/CVE-2017-12166.html

https://www.suse.com/security/cve/CVE-2017-7478.html

https://www.suse.com/security/cve/CVE-2017-7479.html

https://bugzilla.suse.com/1038709

https://bugzilla.suse.com/1038711

https://bugzilla.suse.com/1038713

https://bugzilla.suse.com/1060877

https://bugzilla.suse.com/995374

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2838-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here