PublicDateAtUSN: 2021-04-26 14:15:00 UTC Candidate: CVE-2020-15078 PublicDate: 2021-04-26 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15078 https://community.openvpn.net/openvpn/wiki/CVE-2020-15078 https://ubuntu.com/security/notices/USN-4933-1 Description: OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987380 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_openvpn: upstream: https://github.com/OpenVPN/openvpn/commit/f7b3bf067ffce72e7de49a4174fd17a3a83f0573 (v2.5.2) upstream: https://github.com/OpenVPN/openvpn/commit/3d18e308c4e7e6f7ab7c2826c70d2d07b031c18a (v2.5.2) upstream: https://github.com/OpenVPN/openvpn/commit/3aca477a1b58714754fea3a26d0892fffc51db6b (v2.5.2) upstream: https://github.com/OpenVPN/openvpn/commit/0e5516a9d656ce86f7fb370c824344ea1760c255 (2.4.11) upstream_openvpn: released (2.5.2) precise/esm_openvpn: not-affected (code not present) trusty_openvpn: ignored (out of standard support) trusty/esm_openvpn: not-affected (code not present) xenial_openvpn: not-affected (code not present) esm-infra/xenial_openvpn: not-affected (code not present) bionic_openvpn: released (2.4.4-2ubuntu1.5) focal_openvpn: released (2.4.7-1ubuntu2.20.04.2) groovy_openvpn: released (2.4.9-3ubuntu1.1) hirsute_openvpn: released (2.5.1-1ubuntu1.1) impish_openvpn: released (2.5.1-2) jammy_openvpn: released (2.5.1-2) devel_openvpn: released (2.5.1-2)