Ubuntu security notices
USN-3284-1: OpenVPN vulnerabilities
USN-3284-1: OpenVPN vulnerabilities Ubuntu Security Notice USN-3284-1 11th May, 2017 openvpn vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Summary Several security issues were fixed in OpenVPN. Software description openvpn – virtual private network software Details It was discovered that OpenVPN improperly triggered an assert whenreceiving an oversized control packet in some situations. A remoteattacker could use this to cause a denial of service (server or clientcrash). (CVE-2017-7478) It was discovered that OpenVPN improperly triggered an assert when packetids rolled over. An authenticated remote attacker could use this to cause adenial of service (application crash). (CVE-2017-7479) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: openvpn 2.4.0-4ubuntu1.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all [ more… ]