Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
aports
aports
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 678
    • Issues 678
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Merge Requests 213
    • Merge Requests 213
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Incidents
    • Environments
  • Analytics
    • Analytics
    • CI / CD
    • Repository
    • Value Stream
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • alpine
  • aportsaports
  • Issues
  • #7413

Closed
Open
Opened Jun 11, 2017 by Alicha CH@alichaReporter

[3.5] openvpn: Multiple vulnerabilities (CVE-2017-7478, CVE-2017-7479)

CVE-2017-7478: OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.

Fixed In Version:

openvpn 2.3.15, openvpn 2.4.2

References:

https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7478

Patch:

https://github.com/OpenVPN/openvpn/commit/feb35ee5cac605edddd6e9dc62941e2c53f96fb3

CVE-2017-7479: OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID
counter rolls over resulting into Denial of Service of server by authenticated attacker.

Fixed In Version:

openvpn 2.3.15, openvpn 2.4.2

References:

https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits
https://nvd.nist.gov/vuln/detail/CVE-2017-7479

Patch:

https://github.com/OpenVPN/openvpn/commit/b727643cdf4e078f132a90e1c474a879a5760578

(from redmine: issue id 7413, created on 2017-06-11, closed on 2017-06-14)

  • Changesets:
    • Revision 039751f5 on 2017-06-13T09:50:46Z:
main/openvpn: security upgrade to 2.3.15 (CVE-2017-7478, CVE-2017-7479). Fixes #7413
To upload designs, you'll need to enable LFS and have admin enable hashed storage. More information
Assignee
Assign to
3.5.3
Milestone
3.5.3 (Past due)
Assign milestone
Time tracking
None
Due date
None
Reference: alpine/aports#7413