MGASA-2017-0152
Dashboard / Vulnerabilities / MGASA-2017-0152
Summary: Updated openvpn packages fix security vulnerability
Details: It was discovered that OpenVPN improperly triggered an assert when receiving an oversized control packet in some situations. A remote attacker could use this to cause a denial of service (server or client crash) (CVE-2017-7478). It was discovered that OpenVPN improperly triggered an assert when packet ids rolled over. An authenticated remote attacker could use this to cause a denial of service (application crash) (CVE-2017-7479).
References: https://advisories.mageia.org/MGASA-2017-0152.html, https://bugs.mageia.org/show_bug.cgi?id=20845, https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn23, https://www.ubuntu.com/usn/usn-3284-1/
Affected packages
Package
Name: openvpn
Purl: pkg:rpm/mageia/openvpn?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
