Bug 1185279 - (CVE-2020-15078) VUL-0: CVE-2020-15078: openvpn, openvpn-openssl1: Authentication bypass with deferred authentication
(CVE-2020-15078)
VUL-0: CVE-2020-15078: openvpn, openvpn-openssl1: Authentication bypass with ...
Status: RESOLVED FIXED
: CVE-2020-15077 CVE-2020-36382 (view as bug list)
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/282802/
CVSSv3.1:SUSE:CVE-2020-15078:5.3:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-04-26 07:03 UTC by Robert Frohl
Modified: 2023-02-13 15:15 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-04-26 07:03:17 UTC
rh#1952934

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass
authentication and access control channel data on servers configured with
deferred authentication, which can be used to potentially trigger further
information leaks.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1952934
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15078
Comment 2 Robert Frohl 2021-04-26 11:50:56 UTC
tracking as affected:

- SUSE:SLE-11-SP1:Update/openvpn
- SUSE:SLE-11-SP3:Update/openvpn
- SUSE:SLE-12:Update/openvpn
- SUSE:SLE-15:Update/openvpn

- SUSE:SLE-11-SP3:Updateopenvpn-openssl1
Comment 3 Robert Frohl 2021-04-26 16:07:36 UTC
just saw my typo..

(In reply to Robert Frohl from comment #2)
> tracking as affected:
>
> - SUSE:SLE-11-SP3:Updateopenvpn-openssl1

- SUSE:SLE-11-SP3:Update/openvpn-openssl1
Comment 4 Reinhard Max 2021-05-01 12:17:08 UTC
Not sure if openvpn versions before 2.1 (SLE-11-SP1 and SLE-11-SP3 have 2.0.9) are even vulnerable, because they did not support deferred authentication, so at least the "#ifdef ENABLE_DEF_AUTH" block in the patch won't ever get compiled in there. The rest applies and compiles, but I am not sure if it is needed at all.
Comment 7 Swamp Workflow Management 2021-05-12 13:27:02 UTC
SUSE-SU-2021:1576-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1185279
CVE References: CVE-2018-7544,CVE-2020-15078
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    openvpn-2.3.8-16.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2021-05-12 13:28:19 UTC
SUSE-SU-2021:1577-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1169925,1185279
CVE References: CVE-2018-7544,CVE-2020-11810,CVE-2020-15078
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    openvpn-2.4.3-5.7.1
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    openvpn-2.4.3-5.7.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2021-05-12 13:44:09 UTC
SUSE-SU-2021:14723-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1185279
CVE References: CVE-2018-7544,CVE-2020-15078
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 11-SECURITY (src):    openvpn-openssl1-2.3.2-0.10.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2021-05-15 19:18:04 UTC
openSUSE-SU-2021:0734-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1169925,1185279
CVE References: CVE-2018-7544,CVE-2020-11810,CVE-2020-15078
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    openvpn-2.4.3-lp152.6.3.1
Comment 11 Gianluca Gabrielli 2021-06-04 15:32:53 UTC
*** Bug 1186874 has been marked as a duplicate of this bug. ***
Comment 12 Gianluca Gabrielli 2021-06-04 15:35:22 UTC
*** Bug 1186876 has been marked as a duplicate of this bug. ***
Comment 13 OBSbugzilla Bot 2021-06-07 13:00:06 UTC
This is an autogenerated message for OBS integration:
This bug (1185279) was mentioned in
https://build.opensuse.org/request/show/898085 Factory / openvpn
Comment 15 Robert Frohl 2021-07-14 08:23:21 UTC
opposite to initial assessment, these codestreams are not affected:

- SUSE:SLE-11-SP1:Update/openvpn
- SUSE:SLE-11-SP3:Update/openvpn
Comment 16 Robert Frohl 2021-07-14 08:23:45 UTC
all released, closing