PT-2013-1210 · Openvpn+2 · Openvpn+2

Steffan Karger

·

Publicado

2013-11-15

·

Atualizado

2020-05-12

·

CVE-2013-2061

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to 2.3.1
Description The issue allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher. Multiple vulnerabilities in the OpenVPN package can lead to disruption of integrity and availability of protected information, and exploitation can be carried out remotely.
Recommendations For OpenVPN versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the openvpn decrypt function in crypto.c until a patch is available. Avoid using the CBC mode cipher in UDP mode until the issue is resolved.

Exploit

Correção

Improper Certificate Validation

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1053
BDU:2015-09682
CVE-2013-2061
SUSE-SU-2013_1783-1

Produtos afetados

Alt Linux
Openvpn
Suse