Bug 37239 - openvpn: Denial of service (ES 3.1)
openvpn: Denial of service (ES 3.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 3.1
Other Linux
: P5 normal (vote)
: UCS 3.1-ES
Assigned To: Stefan Gohmann
Janek Walkenhorst
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-12-08 15:41 CET by Moritz Muehlenhoff
Modified: 2015-09-03 12:58 CEST (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments
3.1-openvpn.txt (660 bytes, text/plain)
2015-08-31 16:38 CEST, Stefan Gohmann
Details
3.1-openvpn.txt (992 bytes, text/plain)
2015-09-03 06:03 CEST, Stefan Gohmann
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2014-12-08 15:41:02 CET
CVE-2014-8104

OpenVPN clients using TLS authentication can crash the server by sending a malicious control channel packet to the server, resulting in denial of service.
Comment 1 Stefan Gohmann univentionstaff 2015-08-31 16:38:34 CEST
Created attachment 7145 [details]
3.1-openvpn.txt
Comment 2 Stefan Gohmann univentionstaff 2015-08-31 16:40:16 CEST
 repo_admin.py -U -p openvpn -d squeeze-lts -r 3.1-0-0 -s extsec3.1

openvpn has been built. The new package should be between the old UCS 3.1 package and the UCS 3.2 package.
Comment 3 Janek Walkenhorst univentionstaff 2015-09-02 19:08:59 CEST
The update seems to fix CVE-2013-2061 too, please update the advisory accordingly.

Advisory: otherwise OK
Changelog: OK
Tests (amd64): OK
Comment 4 Stefan Gohmann univentionstaff 2015-09-03 06:03:04 CEST
Created attachment 7153 [details]
3.1-openvpn.txt
Comment 5 Stefan Gohmann univentionstaff 2015-09-03 06:03:24 CEST
(In reply to Janek Walkenhorst from comment #3)
> The update seems to fix CVE-2013-2061 too, please update the advisory
> accordingly.

Done.
Comment 6 Janek Walkenhorst univentionstaff 2015-09-03 11:47:33 CEST
(In reply to Stefan Gohmann from comment #5)
> (In reply to Janek Walkenhorst from comment #3)
> > The update seems to fix CVE-2013-2061 too, please update the advisory
> > accordingly.
> 
> Done.

OK
Comment 7 Janek Walkenhorst univentionstaff 2015-09-03 12:58:55 CEST
Published