OpenVPN DoS Vulnerabilities (CVE-2014-8104)
Release date: 2014-12-01
Updated on: 2014-6 6
Affected Systems:
OpenVPN <2.3.6
OpenVPN Access Server <2.0.11
Description:
Bugtraq id: 71402
CVE (CAN) ID: CVE-2014-8104
OpenVPN is an open-source ssl vpn toolkit.
In versions earlier than OpenVPN 2.3.6 and earlier than OpenVPN Access Server 2.0.11, an error occurred while parsing control channel data packets. Attackers can exploit this vulnerability to trigger assertion failure and cause denial of service.
<* Source: Dragana Damjanovic
Link: http://secunia.com/advisories/62628/
*>
Suggestion:
Vendor patch:
OpenVPN
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-97597e732b
OpenVPN client configuration tutorial in Ubuntu
Build OpenVPN in Ubuntu 10.04
Ubuntu 13.04 VPN (OpenVPN) configuration and connection cannot access the Intranet and Internet at the same time
How to build a secure remote network architecture using OpenVPN in Linux
Setting up an OpenVPN Server on Ubuntu Server 14.04 to protect your privacy
OpenVPN details: click here
OpenVPN: click here
This article permanently updates the link address: