USN-4933-1
Dashboard / Vulnerabilities / USN-4933-1
USN-4933-1
Summary: openvpn vulnerabilities
Details: It was discovered that OpenVPN incorrectly handled certain data channel v2 packets. A remote attacker could possibly use this issue to inject packets using a victim's peer-id. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-11810) It was discovered that OpenVPN incorrectly handled deferred authentication. When a server is configured to use deferred authentication, a remote attacker could possibly use this issue to bypass authentication and access control channel data. (CVE-2020-15078)
References: https://ubuntu.com/security/notices/USN-4933-1, https://ubuntu.com/security/CVE-2020-11810, https://ubuntu.com/security/CVE-2020-15078
Affected packages
Package
Name: openvpn
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
