MGASA-2017-0372
Dashboard / Vulnerabilities / MGASA-2017-0372
Summary: Updated openvpn packages fix security vulnerability
Details: The bounds check in read_key() was performed after using the value, instead of before. If 'key-method 1' is used, this allowed an attacker to send a malformed packet to trigger a stack buffer overflow. Note that 'key-method 1' has been replaced by 'key method 2' as the default in OpenVPN 2.0 (CVE-2017-12166).
References: https://advisories.mageia.org/MGASA-2017-0372.html, https://bugs.mageia.org/show_bug.cgi?id=21780, https://community.openvpn.net/openvpn/wiki/CVE-2017-12166, https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn23, https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24
Affected packages
Package
Name: openvpn
Purl: pkg:rpm/mageia/openvpn?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
