MGASA-2016-0146
Dashboard / Vulnerabilities / MGASA-2016-0146
MGASA-2016-0146
Summary: Updated vtun packages fix security vulnerabilities
Details: Updated vtun package fixes security vulnerability: A vulnerability was found in the vtun package. When you send a SIGHUP to a vtun client process and it cannot connect to the remote server, vtun tries to reconnect without sleep between each attempt. In result, the vtun process uses a lot of CPU, and writes to syslog without limit. The vtun package has been updated to version 3.0.3 and patched to fix this issue and other bugs.
References: https://advisories.mageia.org/MGASA-2016-0146.html, https://bugs.mageia.org/show_bug.cgi?id=18135, https://lists.fedoraproject.org/pipermail/package-announce/2016-April/181383.html
Affected packages
Package
Name: vtun
Purl: pkg:rpm/mageia/vtun?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
