Commit 1050e3

2025-02-27 10:33:42 Samuli Seppänen: Switch to non-AI version
Security Announcements/VulnerabilitiesFixedInOpenSSL1_0_1i.md ..
@@ 1,21 1,21 @@
- # Background
+ # Background
- On August 6, 2014, the OpenSSL project released version 1.0.1i, which addressed [several security vulnerabilities](http://www.openssl.org/news/secadv_20140806.txt) classified as moderate severity or less. These updates were crucial as official OpenVPN Windows installers include OpenSSL 1.0.1, necessitating a [new Windows installer release](http://openvpn.net/index.php/download/community-downloads.html) by the OpenVPN project. On UNIX-based operating systems, upgrading OpenSSL is typically managed by the OS provider.
+ On 6th August 2014 the OpenSSL project released 1.0.1i that fixed [several security vulnerabilities](http://www.openssl.org/news/secadv_20140806.txt) of [moderate severity or less](http://openssl.6102.n7.nabble.com/Forthcoming-OpenSSL-releases-td52456.html). Official OpenVPN Windows installers bundle OpenSSL 1.0.1, which meant that the OpenVPN project had to make a [new Windows installer release](http://openvpn.net/index.php/download/community-downloads.html). On *NIX-based operating systems upgrading OpenSSL is typically handled by the OS provider.
- # List of Vulnerabilities
+ # List of vulnerabilities
- | **Vulnerability Name** | **ID** | **Affects OpenVPN?** |
- |-------------------------------------------------------------|--------------|----------------------|
- | Information leak in pretty printing functions | CVE-2014-3508| Possibly[1]. |
- | Crash with SRP ciphersuite in Server Hello message | CVE-2014-5139| No. OpenVPN does not use SRP. |
- | Race condition in ssl_parse_serverhello_tlsext | CVE-2014-3509| No. |
- | Double Free when processing DTLS packets | CVE-2014-3505| No. OpenVPN does not use DTLS. |
- | DTLS memory exhaustion | CVE-2014-3506| No. OpenVPN does not use DTLS. |
- | DTLS memory leak from zero-length fragments | CVE-2014-3507| No. OpenVPN does not use DTLS. |
- | OpenSSL DTLS anonymous EC(DH) denial of service | CVE-2014-3510| No. OpenVPN does not use DTLS. |
- | OpenSSL TLS protocol downgrade attack | CVE-2014-3511| No. OpenVPN already defaults to TLS 1.0 [2]. |
- | SRP buffer overrun | CVE-2014-3512| No. OpenVPN does not use SRP. |
+ |**Vulnerability name**|**ID**|**Affects OpenVPN?**|
+ |-|-|-|
+ |Information leak in pretty printing functions|CVE-2014-3508|Possibly[1].|
+ |Crash with SRP ciphersuite in Server Hello message|CVE-2014-5139|No. OpenVPN does not use SRP.|
+ |Race condition in ssl_parse_serverhello_tlsext|CVE-2014-3509|No.|
+ |Double Free when processing DTLS packets|CVE-2014-3505|No. OpenVPN does not use DTLS.|
+ |DTLS memory exhaustion|CVE-2014-3506|No. OpenVPN does not use DTLS.|
+ |DTLS memory leak from zero-length fragments|CVE-2014-3507|No. OpenVPN does not use DTLS.|
+ |OpenSSL DTLS anonymous EC(DH) denial of service|CVE-2014-3510|No. OpenVPN does not use DTLS.|
+ |OpenSSL TLS protocol downgrade attack|CVE-2014-3511|No. OpenVPN already defaults to TLS 1.0 [2].|
+ |SRP buffer overrun|CVE-2014-3512|No. OpenVPN does not use SRP.|
- [1] This vulnerability does not directly affect OpenVPN. While leaked information is not transmitted to peers by OpenVPN, it might be possible that this information is passed on to a client script or plugin. The form of the leaked information and whether it is exported beyond a NULL-byte is uncertain. Such a plugin/script could potentially leak the information to an attacker.
+ [1] This one triggers no direct vulnerability in OpenVPN. Leaked information is not sent to peers by OpenVPN. It might be possible that the leaked information is passed on to a client script / plugin (not sure what form the leaked information has, if the leaked information is after a NUL-byte, it's probably not even exported). Such a plugin/script could then leak the information to the attacker.
- [2] If you are using OpenVPN 2.3.3 or OpenVPN 2.3.4 and have enabled newer TLS versions by using the `tls-version-min` option in your configuration, your setup is susceptible to the protocol downgrade attack. Nonetheless, it remains at least as secure as a configuration without the `tls-version-min` option.
\ No newline at end of file
+ [2] If you are using OpenVPN 2.3.3 or OpenVPN 2.3.4 and have enabled newer TLS versions by using option tls-version-min in your configuration, your configuration is vulnerable to the protocol downgrade attack. However, it will still be at least as secure as a setup without tls-version-min in its configuration.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9