Background
On August 6, 2014, the OpenSSL project released version 1.0.1i, which addressed several security vulnerabilities classified as moderate severity or less. These updates were crucial as official OpenVPN Windows installers include OpenSSL 1.0.1, necessitating a new Windows installer release by the OpenVPN project. On UNIX-based operating systems, upgrading OpenSSL is typically managed by the OS provider.
List of Vulnerabilities
| Vulnerability Name | ID | Affects OpenVPN? |
|---|---|---|
| Information leak in pretty printing functions | CVE-2014-3508 | Possibly[1]. |
| Crash with SRP ciphersuite in Server Hello message | CVE-2014-5139 | No. OpenVPN does not use SRP. |
| Race condition in ssl_parse_serverhello_tlsext | CVE-2014-3509 | No. |
| Double Free when processing DTLS packets | CVE-2014-3505 | No. OpenVPN does not use DTLS. |
| DTLS memory exhaustion | CVE-2014-3506 | No. OpenVPN does not use DTLS. |
| DTLS memory leak from zero-length fragments | CVE-2014-3507 | No. OpenVPN does not use DTLS. |
| OpenSSL DTLS anonymous EC(DH) denial of service | CVE-2014-3510 | No. OpenVPN does not use DTLS. |
| OpenSSL TLS protocol downgrade attack | CVE-2014-3511 | No. OpenVPN already defaults to TLS 1.0 [2]. |
| SRP buffer overrun | CVE-2014-3512 | No. OpenVPN does not use SRP. |
[1] This vulnerability does not directly affect OpenVPN. While leaked information is not transmitted to peers by OpenVPN, it might be possible that this information is passed on to a client script or plugin. The form of the leaked information and whether it is exported beyond a NULL-byte is uncertain. Such a plugin/script could potentially leak the information to an attacker.
[2] If you are using OpenVPN 2.3.3 or OpenVPN 2.3.4 and have enabled newer TLS versions by using the tls-version-min option in your configuration, your setup is susceptible to the protocol downgrade attack. Nonetheless, it remains at least as secure as a configuration without the tls-version-min option.
