OpenVPN Deny Service Vulnerability
Last Update Date:
3 Dec 2014 10:05
Release Date:
3 Dec 2014
3755
Views
RISK: Medium Risk
TYPE: Servers - Network Management
A vulnerability was reported in OpenVPN. A remote authenticated user can cause denial of service conditions.
A remote authenticated user (TLS-authenticated using certificates) can send a specially crafted control channel packet to cause the target service to crash.
Version 3.x is not affected.
Impact
- Denial of Service
System / Technologies affected
- OpenVPN version 2.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (2.3.6).
http://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-97597e732b
Vulnerability Identifier
Source
Related Link
Share with