OpenVPN Server Remote Denial Of Service Vulnerability
BID:15270
Info
OpenVPN Server Remote Denial Of Service Vulnerability
| Bugtraq ID: | 15270 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-3409 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2005 12:00AM |
| Updated: | Mar 24 2006 06:14PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 OpenVPN OpenVPN 2.0.2 OpenVPN OpenVPN 2.0.1 OpenVPN OpenVPN 2.0 beta11 OpenVPN OpenVPN 2.0 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.4 OpenPKG OpenPKG 2.3 OpenPKG OpenPKG Current Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Multi Network Firewall 2.0 Gentoo Linux |
| Not Vulnerable: |
OpenVPN OpenVPN 2.0.4 |
Discussion
OpenVPN Server Remote Denial Of Service Vulnerability
OpenVPN server is prone to a remote denial-of-service vulnerability. Due to a design error, the server won't be able to handle exceptional conditions while running in TCP mode.
This issue affects all OpenVPN 2.0 versions; the vendor has released version 2.0.4 to address this issue.
OpenVPN server is prone to a remote denial-of-service vulnerability. Due to a design error, the server won't be able to handle exceptional conditions while running in TCP mode.
This issue affects all OpenVPN 2.0 versions; the vendor has released version 2.0.4 to address this issue.
Exploit / POC
OpenVPN Server Remote Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
OpenVPN Server Remote Denial Of Service Vulnerability
Solution:
The vendor has released version 2.0.4 to address this issue; please see the reference section for more information.
OpenVPN OpenVPN 2.0
OpenVPN OpenVPN 2.0 beta11
OpenVPN OpenVPN 2.0.1
OpenVPN OpenVPN 2.0.2
OpenPKG OpenPKG 2.5
Solution:
The vendor has released version 2.0.4 to address this issue; please see the reference section for more information.
OpenVPN OpenVPN 2.0
-
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
OpenVPN OpenVPN 2.0 beta11
-
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
OpenVPN OpenVPN 2.0.1
-
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
OpenVPN OpenVPN 2.0.2
-
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
OpenPKG OpenPKG 2.5
-
OpenPKG openvpn-2.0-2.4.1.src.rpm
OpenPKG 2.5
ftp://ftp.openpkg.org/release/2.4/UPD/openvpn-2.0-2.4.1.src.rpm -
OpenPKG openvpn-2.0.2-2.5.1.src.rpm
OpenPKG 2.5
ftp://ftp.openpkg.org/release/2.5/UPD/openvpn-2.0.2-2.5.1.src.rpm
References
OpenVPN Server Remote Denial Of Service Vulnerability
References:
References:
- OpenVPN Change Log (OpenVPN)
- OpenVPN Homepage (OpenVPN)