USN-3339-1: OpenVPN vulnerabilities
USN-3339-1: OpenVPN vulnerabilities Ubuntu Security Notice USN-3339-1 22nd June, 2017 openvpn vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in OpenVPN. Software description openvpn – virtual private network software Details Karthikeyan Bhargavan and Gaëtan Leurent discovered that 64-bit blockciphers are vulnerable to a birthday attack. A remote attacker couldpossibly use this issue to recover cleartext data. Fixing this issuerequires a configuration change to switch to a different cipher. Thisupdate adds a warning to the log file when a 64-bit block cipher is in use.This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS andUbuntu 16.10. (CVE-2016-6329) It was discovered that OpenVPN incorrectly handled rollover of packet ids.An authenticated remote attacker could use this issue to cause OpenVPN tocrash, resulting in [ more… ]