QID 198352

Date Published: 2021-05-10

QID 198352: Ubuntu Security Notification for OpenVPN vulnerabilities (USN-4933-1)

Openvpn incorrectly handled deferred authentication

A remote attacker could possibly use this issue to inject packets using a victim's peer-id
This issue only affected Ubuntu 1804 LTS and Ubuntu 2004 LTS
(CVE-2020-11810) When a server is configured to use deferred authentication, a remote attacker could possibly use this issue to bypass authentication and access control channel data
(CVE-2020-15078)

  • CVSS V3 rated as Medium - 3.7 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4933-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198352

    Software Advisories
    Advisory ID Software Component Link
    USN-4933-1 Ubuntu Linux URL Logo usn.ubuntu.com/4933-1