Bug 1038713 - VUL-1: openvpn: Include hardening measures found by audit
VUL-1: openvpn: Include hardening measures found by audit
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-05-11 14:33 UTC by Johannes Segitz
Modified: 2018-02-12 21:07 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2017-05-11 14:33:12 UTC
Findings described in 
https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits

Quarkslab 5.1 (CVE-2017-7478, bsc#1038709)
and
Quarkslab 5.2 (CVE-2017-7479, bsc#1038711) 
are tracked seperately.
Comment 3 Bernhard Wiedemann 2017-06-02 10:02:09 UTC
This is an autogenerated message for OBS integration:
This bug (1038713) was mentioned in
https://build.opensuse.org/request/show/500570 42.2 / openvpn
https://build.opensuse.org/request/show/500580 42.3 / openvpn
Comment 4 Swamp Workflow Management 2017-06-20 10:12:08 UTC
SUSE-SU-2017:1622-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1038709,1038711,1038713,995374
CVE References: CVE-2016-6329,CVE-2017-7478,CVE-2017-7479
Sources used:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    openvpn-2.3.8-16.14.1
SUSE Linux Enterprise Server 12-SP2 (src):    openvpn-2.3.8-16.14.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    openvpn-2.3.8-16.14.1
Comment 5 Swamp Workflow Management 2017-06-21 16:13:06 UTC
openSUSE-SU-2017:1638-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1038709,1038711,1038713,995374
CVE References: CVE-2016-6329,CVE-2017-7478,CVE-2017-7479
Sources used:
openSUSE Leap 42.2 (src):    openvpn-2.3.8-8.6.1
Comment 7 Swamp Workflow Management 2017-06-29 16:13:08 UTC
SUSE-SU-2017:1718-1: An update that solves 5 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1038709,1038711,1038713,1044947,959511,988522
CVE References: CVE-2017-7478,CVE-2017-7479,CVE-2017-7508,CVE-2017-7520,CVE-2017-7521
Sources used:
SUSE Linux Enterprise Server 11-SECURITY (src):    openvpn-openssl1-2.3.2-0.9.1
Comment 9 Swamp Workflow Management 2017-10-24 13:07:47 UTC
SUSE-SU-2017:2838-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1038709,1038711,1038713,1060877,995374
CVE References: CVE-2016-6329,CVE-2017-12166,CVE-2017-7478,CVE-2017-7479
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    openvpn-2.0.9-143.47.3.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    openvpn-2.0.9-143.47.3.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    openvpn-2.0.9-143.47.3.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    openvpn-2.0.9-143.47.3.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    openvpn-2.0.9-143.47.3.1
Comment 10 Marcus Meissner 2018-02-12 21:07:52 UTC
released