Login
Newsletter
Werbung

Sicherheit: Denial of Service in OpenVPN
Aktuelle Meldungen Distributionen
Name: Denial of Service in OpenVPN
ID: USN-2430-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10
Datum: Di, 2. Dezember 2014, 17:34
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8104
Applikationen: OpenVPN

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============7927965511966916553==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="qfAktStuUXCkijT3kNvRjIOXIO60GouD5"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--qfAktStuUXCkijT3kNvRjIOXIO60GouD5
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2430-1
December 02, 2014

openvpn vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

OpenVPN could be made to crash if it received specially crafted network
traffic.

Software Description:
- openvpn: virtual private network software

Details:

Dragana Damjanovic discovered that OpenVPN incorrectly handled certain
control channel packets. An authenticated attacker could use this issue to
cause an OpenVPN server to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.10:
openvpn 2.3.2-9ubuntu1.1

Ubuntu 14.04 LTS:
openvpn 2.3.2-7ubuntu3.1

Ubuntu 12.04 LTS:
openvpn 2.2.1-8ubuntu1.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2430-1
CVE-2014-8104

Package Information:
https://launchpad.net/ubuntu/+source/openvpn/2.3.2-9ubuntu1.1
https://launchpad.net/ubuntu/+source/openvpn/2.3.2-7ubuntu3.1
https://launchpad.net/ubuntu/+source/openvpn/2.2.1-8ubuntu1.4



--qfAktStuUXCkijT3kNvRjIOXIO60GouD5
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUfddnAAoJEGVp2FWnRL6TL2cQAKZgQMAsJVT6O5Ea7QAh1h3q
STXQgwsRP3c/GKbNM/FTYJEv2NfBoB9Fs+bgBYX9f8YhnwZT7k34DIdltIWVY75X
8Cu7m5Qu+bkCRKkuqMAoPkb4a2z9clbmPtpDGM9UN0SmHiIxfH0mxXMvVImEkBvf
7TEYF47livxglBRCj0Br8BCqkAuUh9jpIY2UfpNzeHudPdrL0zvbINORbzfFu1G5
Kc+xIb6ZKgvDnruLYvKRAb1/swrIkQI4+mx1ishpgp1BCe/0p/Y8v8d3OVFX+LeT
JtaY/z65vNb5k622kgdmakAgd6haW4Li7yIZOTZndzVJOvsUFb4PGXHrmqXEG9T0
3ZXRQ2eiY8qCjAxIHyJrFQngwEWo+TUBzu0wwSMkI/k67j0HNMKE4Cr2nQzVH4Qu
nIV390Wz4/R+kzzHfsz1O/qq9A5fo+A8RLgLJ5QlzooqXYmPnn8rXGbYDaASXPtK
G+opZ6zzHeCIucgVfZDVZ8AgMbkUyRH4TXp6kG6v5aWKgYFw46C1/jtApwW6R+n1
vIkoH96aec4FD7g+nbXWmypHAe3LD4oJo4VrjfVBps67NlYOiZ2XCxsVs8dbh6xF
D8cnn2zPU59Qz8Ie7aCTVG8E64CQZIwopqwLwMINMSC77vwXgj/7SKpH6oxsafAL
O9W2FcuYfMl8Lso3nau7
=mc1e
-----END PGP SIGNATURE-----

--qfAktStuUXCkijT3kNvRjIOXIO60GouD5--


--===============7927965511966916553==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============7927965511966916553==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung