Blame
| d394b8 | Samuli Seppänen | 2025-02-27 10:34:57 | 1 | # Background |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| d394b8 | Samuli Seppänen | 2025-02-27 10:34:57 | 3 | On 15th Oct 2014 the OpenSSL project released 1.0.1j that fixed [several security vulnerabilities](http://www.openssl.org/news/secadv_20141015.txt) of high severity or less. Official OpenVPN Windows installers bundle OpenSSL 1.0.1, which meant that the OpenVPN project had to make a [new Windows installer release](http://openvpn.net/index.php/download/community-downloads.html) (I004/I604). On *NIX-based operating systems OpenSSL is typically dynamically linked to OpenVPN and the OS provider handles the OpenSSL upgrades. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| d394b8 | Samuli Seppänen | 2025-02-27 10:34:57 | 5 | # List of vulnerabilities |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 6 | |
| d394b8 | Samuli Seppänen | 2025-02-27 10:34:57 | 7 | |**Vulnerability name**|**ID**|**Affects OpenVPN?**|**Mitigation**| |
| 8 | |-|-|-|-| |
|||
| 9 | |SRTP Memory Leak|CVE-2014-3513|Denial-of-service only|TLS auth can[1] protect against this vulnerability| |
|||
| 10 | |Session Ticket Memory Leak|CVE-2014-3567|Denial-of-service only|TLS auth can[1] protect against this vulnerability| |
|||
| 11 | |SSL 3.0 Fallback protection|CVE-2014-3568|No SSLv3 in OpenVPN, not affected| |
|||
| 12 | |Build option no-ssl3 is incomplete|-|No SSLv3 in OpenVPN, not affected| |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 13 | |
| 14 | Analysis of the impact of these vulnerabilities is taken from [here](http://thread.gmane.org/gmane.network.openvpn.devel/9133/focus=9139). |
|||
| 15 | ||||
| d394b8 | Samuli Seppänen | 2025-02-27 10:34:57 | 16 | [1] The amount of protection is limited in environments where the TLS auth key is widely distributed (large organizations) or public (VPN service providers). |
