Blame
| 1050e3 | Samuli Seppänen | 2025-02-27 10:33:42 | 1 | # Background |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| 1050e3 | Samuli Seppänen | 2025-02-27 10:33:42 | 3 | On 6th August 2014 the OpenSSL project released 1.0.1i that fixed [several security vulnerabilities](http://www.openssl.org/news/secadv_20140806.txt) of [moderate severity or less](http://openssl.6102.n7.nabble.com/Forthcoming-OpenSSL-releases-td52456.html). Official OpenVPN Windows installers bundle OpenSSL 1.0.1, which meant that the OpenVPN project had to make a [new Windows installer release](http://openvpn.net/index.php/download/community-downloads.html). On *NIX-based operating systems upgrading OpenSSL is typically handled by the OS provider. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| 1050e3 | Samuli Seppänen | 2025-02-27 10:33:42 | 5 | # List of vulnerabilities |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 6 | |
| 1050e3 | Samuli Seppänen | 2025-02-27 10:33:42 | 7 | |**Vulnerability name**|**ID**|**Affects OpenVPN?**| |
| 8 | |-|-|-| |
|||
| 9 | |Information leak in pretty printing functions|CVE-2014-3508|Possibly[1].| |
|||
| 10 | |Crash with SRP ciphersuite in Server Hello message|CVE-2014-5139|No. OpenVPN does not use SRP.| |
|||
| 11 | |Race condition in ssl_parse_serverhello_tlsext|CVE-2014-3509|No.| |
|||
| 12 | |Double Free when processing DTLS packets|CVE-2014-3505|No. OpenVPN does not use DTLS.| |
|||
| 13 | |DTLS memory exhaustion|CVE-2014-3506|No. OpenVPN does not use DTLS.| |
|||
| 14 | |DTLS memory leak from zero-length fragments|CVE-2014-3507|No. OpenVPN does not use DTLS.| |
|||
| 15 | |OpenSSL DTLS anonymous EC(DH) denial of service|CVE-2014-3510|No. OpenVPN does not use DTLS.| |
|||
| 16 | |OpenSSL TLS protocol downgrade attack|CVE-2014-3511|No. OpenVPN already defaults to TLS 1.0 [2].| |
|||
| 17 | |SRP buffer overrun|CVE-2014-3512|No. OpenVPN does not use SRP.| |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 18 | |
| 1050e3 | Samuli Seppänen | 2025-02-27 10:33:42 | 19 | [1] This one triggers no direct vulnerability in OpenVPN. Leaked information is not sent to peers by OpenVPN. It might be possible that the leaked information is passed on to a client script / plugin (not sure what form the leaked information has, if the leaked information is after a NUL-byte, it's probably not even exported). Such a plugin/script could then leak the information to the attacker. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 20 | |
| 1050e3 | Samuli Seppänen | 2025-02-27 10:33:42 | 21 | [2] If you are using OpenVPN 2.3.3 or OpenVPN 2.3.4 and have enabled newer TLS versions by using option tls-version-min in your configuration, your configuration is vulnerable to the protocol downgrade attack. However, it will still be at least as secure as a setup without tls-version-min in its configuration. |
