OESA-2021-1197
Dashboard / Vulnerabilities / OESA-2021-1197
Summary: openvpn security update
Details: OpenVPN is a full-featured open source SSL VPN solution that accommodates a wide range of configurations, including remote access, site-to-site VPNs, Wi-Fi security, and enterprise-scale remote access solutions with load balancing, failover, and fine-grained access-controls. Starting with the fundamental premise that complexity is the enemy of security, OpenVPN offers a cost-effective, lightweight alternative to other VPN technologies that is well-adapted for the SME and enterprise markets. Security Fix(es): OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.(CVE-2020-15078)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1197, https://nvd.nist.gov/vuln/detail/CVE-2020-15078
Affected packages
Package
Name: openvpn
Purl: pkg:rpm/openEuler/openvpn&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
