Candidate: CVE-2017-12166 PublicDate: 2017-10-04 01:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12166 https://community.openvpn.net/openvpn/wiki/CVE-2017-12166 http://www.openwall.com/lists/oss-security/2017/09/28/2 Description: OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution. Ubuntu-Description: sbeattie> vulnerable only in configurations that have 'key method 1’ set. Notes: Bugs: Priority: low Discovered-by: Guido Vranken Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_openvpn: upstream: https://community.openvpn.net/openvpn/changeset/3b1a61e9fb27213c46f76312f4065816bee8ed01/ (master) upstream: https://community.openvpn.net/openvpn/changeset/c7e259160b28e94e4ea7f0ef767f8134283af255/ (release/2.4) upstream: https://community.openvpn.net/openvpn/changeset/fce34375295151f548a26c2d0eb30141e427c81a/ (release/2.3) upstream: https://community.openvpn.net/openvpn/changeset/a9f5c744d6b09f2495ca48d2c926efd3a4b981e6/ (release/2.2) upstream_openvpn: released (2.4.4, 2.3.18) precise/esm_openvpn: ignored (end of ESM support, was needed) trusty_openvpn: ignored (reached end-of-life) trusty/esm_openvpn: needed vivid/ubuntu-core_openvpn: DNE xenial_openvpn: ignored (end of standard support, was needed) esm-infra/xenial_openvpn: needed zesty_openvpn: ignored (reached end-of-life) artful_openvpn: ignored (reached end-of-life) bionic_openvpn: not-affected (2.4.4-2ubuntu1) cosmic_openvpn: ignored (reached end-of-life) disco_openvpn: ignored (reached end-of-life) eoan_openvpn: not-affected (2.4.7-1ubuntu2) focal_openvpn: not-affected (2.4.7-1ubuntu2) groovy_openvpn: not-affected (2.4.7-1ubuntu2) hirsute_openvpn: not-affected (2.4.7-1ubuntu2) impish_openvpn: not-affected (2.4.7-1ubuntu2) jammy_openvpn: not-affected (2.4.7-1ubuntu2) devel_openvpn: not-affected (2.4.7-1ubuntu2)