Skip to main content

OpenVPN Deny Service Vulnerability

Last Update Date: 3 Dec 2014 10:05 Release Date: 3 Dec 2014 3219 Views

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability was reported in OpenVPN. A remote authenticated user can cause denial of service conditions.

 

A remote authenticated user (TLS-authenticated using certificates) can send a specially crafted control channel packet to cause the target service to crash.

 

Version 3.x is not affected.


Impact

  • Denial of Service

System / Technologies affected

  • OpenVPN version 2.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link