=========================================================================Ubuntu Security Notice USN-2368-1
October 02, 2014

openvpn vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

OpenVPN could be made to expose sensitive information over the network.

Software Description:
- openvpn: virtual private network software

Details:

It was discovered that OpenVPN incorrectly handled HMAC comparisons when
running in UDP mode. If a remote attacker were able to perform a
man-in-the-middle attack, this flaw could possibly be used to perform a
plaintext recovery attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  openvpn                         2.2.1-8ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2368-1
  CVE-2013-2061

Package Information:
  https://launchpad.net/ubuntu/+source/openvpn/2.2.1-8ubuntu1.3


Ubuntu 2368-1: OpenVPN vulnerability

October 2, 2014
OpenVPN could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: openvpn 2.2.1-8ubuntu1.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2368-1

CVE-2013-2061

Severity
October 02, 2014

Package Information

https://launchpad.net/ubuntu/+source/openvpn/2.2.1-8ubuntu1.3

Related News