Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2018:1888-1 Moderate: OpenVPN Denial of Service Issue

suse
Calendar Grey July 5, 2018
Scroller Suse
The SUSE Security Update for OpenVPN addresses CVE-2018-9336, a moderate severity vulnerability that could lead to unauthorized access or data leaks
An update that fixes one vulnerability is now available

Summary

This update for openvpn fixes the following issues: - CVE-2018-9336: Fix potential double-free() in Interactive Service could lead to denial of service (bsc#1090839). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1284=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): openvpn-2.4.3-5.3.19 openvpn-auth-pam-plugin-2.4.3-5.3.19 openvpn-auth-pam-plugin-debuginfo-2.4.3-5.3.19 openvpn-debuginfo-2.4.3-5.3.19 openvpn-debugsource-2.4.3-5.3.19 openvpn-devel-2.4.3-5.3.19

References

#1090839

Cross- CVE-2018-9336

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-9336.html

https://bugzilla.suse.com/1090839

Announcement ID: SUSE-SU-2018:1888-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.