Background
On 15th Oct 2014, the OpenSSL project released version 1.0.1j that addressed several security vulnerabilities of high severity or less. Official OpenVPN Windows installers bundle OpenSSL 1.0.1, necessitating a new Windows installer release (I004/I604) by the OpenVPN project. On *NIX-based operating systems, OpenSSL is typically dynamically linked to OpenVPN, and the OS provider manages OpenSSL upgrades.
List of vulnerabilities
| Vulnerability name | ID | Affects OpenVPN? | Mitigation |
|---|---|---|---|
| SRTP Memory Leak | CVE-2014-3513 | Denial-of-service only | TLS auth can1 protect against this vulnerability |
| Session Ticket Memory Leak | CVE-2014-3567 | Denial-of-service only | TLS auth can1 protect against this vulnerability |
| SSL 3.0 Fallback protection | CVE-2014-3568 | No SSLv3 in OpenVPN, not affected | N/A |
| Build option no-ssl3 is incomplete | - | No SSLv3 in OpenVPN, not affected | N/A |
Analysis of the impact of these vulnerabilities is taken from here.
