PublicDateAtUSN: 2013-11-17 Candidate: CVE-2013-2061 PublicDate: 2013-11-18 02:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2061 https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-f375aa67cc https://ubuntu.com/security/notices/USN-2368-1 Description: The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=707329 https://bugs.launchpad.net/bugs/1184223 Priority: low Discovered-by: Assigned-to: CVSS: Patches_openvpn: upstream: https://github.com/OpenVPN/openvpn/commit/11d21349a4e7e38a025849479b36ace7c2eec2ee upstream_openvpn: released (2.3.1) hardy_openvpn: ignored (reached end-of-life) lucid_openvpn: ignored (reached end-of-life) oneiric_openvpn: ignored (reached end-of-life) precise_openvpn: released (2.2.1-8ubuntu1.3) quantal_openvpn: ignored (reached end-of-life) raring_openvpn: ignored (reached end-of-life) saucy_openvpn: not-affected (2.3.1-2ubuntu1) trusty_openvpn: not-affected (2.3.1-2ubuntu1) trusty/esm_openvpn: not-affected (2.3.1-2ubuntu1) devel_openvpn: not-affected (2.3.1-2ubuntu1)