Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 12.04 LTS USN-2368-1 Critical: OpenVPN Network Exposure Risk

Ubuntu Large Esm H500
OpenVPN could be made to expose sensitive information over the network.
=========================================================================Ubuntu Security Notice USN-2368-1
October 02, 2014

openvpn vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

OpenVPN could be made to expose sensitive information over the network.

Software Description:
- openvpn: virtual private network software

Details:

It was discovered that OpenVPN incorrectly handled HMAC comparisons when
running in UDP mode. If a remote attacker were able to perform a
man-in-the-middle attack, this flaw could possibly be used to perform a
plaintext recovery attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  openvpn                         2.2.1-8ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
  
  CVE-2013-2061

Package Information:
  https://launchpad.net/ubuntu/+source/openvpn/2.2.1-8ubuntu1.3


Ubuntu 12.04 LTS USN-2368-1 Critical: OpenVPN Network Exposure Risk

ubuntu
Calendar Grey October 2, 2014
Dist Ubuntu Esm H88
Ubuntu 2369-2 resolves a vulnerability in OpenVPN that can potentially leak sensitive network data during certain types of cyber attacks.
OpenVPN could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: openvpn 2.2.1-8ubuntu1.3 In general, a standard system update will make all the necessary changes.

References

CVE-2013-2061

Severity
critical
Lowest
Low
Medium
High
Critical

October 02, 2014

Package Information

https://launchpad.net/ubuntu/+source/openvpn/2.2.1-8ubuntu1.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here