Background

On 15th Oct 2014, the OpenSSL project released version 1.0.1j that addressed several security vulnerabilities of high severity or less. Official OpenVPN Windows installers bundle OpenSSL 1.0.1, necessitating a new Windows installer release (I004/I604) by the OpenVPN project. On *NIX-based operating systems, OpenSSL is typically dynamically linked to OpenVPN, and the OS provider manages OpenSSL upgrades.

List of vulnerabilities

Vulnerability name ID Affects OpenVPN? Mitigation
SRTP Memory Leak CVE-2014-3513 Denial-of-service only TLS auth can1 protect against this vulnerability
Session Ticket Memory Leak CVE-2014-3567 Denial-of-service only TLS auth can1 protect against this vulnerability
SSL 3.0 Fallback protection CVE-2014-3568 No SSLv3 in OpenVPN, not affected N/A
Build option no-ssl3 is incomplete - No SSLv3 in OpenVPN, not affected N/A

Analysis of the impact of these vulnerabilities is taken from here.


  1. a, b The amount of protection is limited in environments where the TLS auth key is widely distributed (large organizations) or public (VPN service providers).

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9