PublicDateAtUSN: 2017-05-11 14:00:00 UTC Candidate: CVE-2017-7478 CRD: 2017-05-11 14:00:00 UTC PublicDate: 2017-05-15 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7478 https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits https://ubuntu.com/security/notices/USN-3284-1 Description: OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2. Ubuntu-Description: It was discovered that OpenVPN improperly triggered an assert when receiving an oversized control packet. A remote attacker could use this to cause a denial of service (server or client crash). Notes: sbeattie> introduced in 3c1b19e04745177185decd14da82c71458442b82 sbeattie> (2.4.0); also was backported to 2.3 in sbeattie> 358f513c008bf01fadb82759ac75ffb8613fc785 (2.3.12) Bugs: https://launchpad.net/bugs/1691531 Priority: high Discovered-by: Assigned-to: sbeattie CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_openvpn: upstream_openvpn: released (2.4.0-5) precise_openvpn: not-affected precise/esm_openvpn: not-affected trusty_openvpn: not-affected trusty/esm_openvpn: not-affected vivid/stable-phone-overlay_openvpn: not-affected vivid/ubuntu-core_openvpn: DNE xenial_openvpn: not-affected esm-infra/xenial_openvpn: not-affected yakkety_openvpn: not-affected zesty_openvpn: released (2.4.0-4ubuntu1.2) devel_openvpn: not-affected (2.4.0-5ubuntu1)