Lucene search

K
ubuntuUbuntuUSN-2368-1
HistoryOct 02, 2014 - 12:00 a.m.

OpenVPN vulnerability

2014-10-0200:00:00
ubuntu.com
51

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.006

Percentile

77.9%

Releases

  • Ubuntu 12.04

Packages

  • openvpn - virtual private network software

Details

It was discovered that OpenVPN incorrectly handled HMAC comparisons when
running in UDP mode. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could possibly be used to perform a
plaintext recovery attack.

OSVersionArchitecturePackageVersionFilename
Ubuntu12.04noarchopenvpn< 2.2.1-8ubuntu1.3UNKNOWN

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.006

Percentile

77.9%