CVE-2014-8104
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-8104
Vendor advisory: secalert@redhat.com — https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-97597e732b
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| suse | 12.3 | affected | |
| suse | 13.1 | affected | |
| suse | 13.2 | affected | |
| debian | 7.0 | affected | |
| debian | 8.0 | affected | |
| ubuntu | 12.04 | affected | |
| ubuntu | 14.04 | affected | |
| ubuntu | 14.10 | affected | |
| debian | bookworm | fixed | 2.3.4-5 |
| debian | bullseye | fixed | 2.3.4-5 |
| debian | forky | fixed | 2.3.4-5 |
| debian | sid | fixed | 2.3.4-5 |
| debian | trixie | fixed | 2.3.4-5 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openvpn | openvpn | 2.0.1_rc1 | |
| openvpn | openvpn | 2.0.1_rc2 | |
| openvpn | openvpn | 2.0.1_rc3 | |
| openvpn | openvpn | 2.0.1_rc4 | |
| openvpn | openvpn | 2.0.1_rc5 | |
| openvpn | openvpn | 2.0.1_rc6 | |
| openvpn | openvpn | 2.0.1_rc7 | |
| openvpn | openvpn | 2.0.2_rc1 | |
| openvpn | openvpn | 2.0.3_rc1 | |
| openvpn | openvpn | 2.0.4 | |
| openvpn | openvpn | 2.0.6_rc1 | |
| openvpn | openvpn | 2.0.9 | |
| openvpn | openvpn | 2.0_rc1 | |
| openvpn | openvpn | 2.0_rc2 | |
| openvpn | openvpn | 2.0_rc3 | |
| openvpn | openvpn | 2.0_rc4 | |
| openvpn | openvpn | 2.0_rc5 | |
| openvpn | openvpn | 2.0_rc6 | |
| openvpn | openvpn | 2.0_rc7 | |
| openvpn | openvpn | 2.0_rc8 | |
| openvpn | openvpn | 2.0_rc9 | |
| openvpn | openvpn | 2.0_rc10 | |
| openvpn | openvpn | 2.0_rc11 | |
| openvpn | openvpn | 2.0_rc12 | |
| openvpn | openvpn | 2.0_rc13 | |
| openvpn | openvpn | 2.0_rc14 | |
| openvpn | openvpn | 2.0_rc15 | |
| openvpn | openvpn | 2.0_rc16 | |
| openvpn | openvpn | 2.0_rc17 | |
| openvpn | openvpn | 2.0_rc18 | |
| openvpn | openvpn | 2.0_rc19 | |
| openvpn | openvpn | 2.0_rc20 | |
| openvpn | openvpn | 2.0_rc21 | |
| openvpn | openvpn | 2.0_test1 | |
| openvpn | openvpn | 2.0_test2 | |
| openvpn | openvpn | 2.0_test3 | |
| openvpn | openvpn | 2.0_test4 | |
| openvpn | openvpn | 2.0_test5 | |
| openvpn | openvpn | 2.0_test6 | |
| openvpn | openvpn | 2.0_test7 | |
| openvpn | openvpn | 2.0_test8 | |
| openvpn | openvpn | 2.0_test9 | |
| openvpn | openvpn | 2.0_test10 | |
| openvpn | openvpn | 2.0_test11 | |
| openvpn | openvpn | 2.0_test12 | |
| openvpn | openvpn | 2.0_test14 | |
| openvpn | openvpn | 2.0_test15 | |
| openvpn | openvpn | 2.0_test16 | |
| openvpn | openvpn | 2.0_test17 | |
| openvpn | openvpn | 2.0_test18 | |
| openvpn | openvpn | 2.0_test19 | |
| openvpn | openvpn | 2.0_test20 | |
| openvpn | openvpn | 2.0_test21 | |
| openvpn | openvpn | 2.0_test22 | |
| openvpn | openvpn | 2.0_test23 | |
| openvpn | openvpn | 2.0_test24 | |
| openvpn | openvpn | 2.0_test25 | |
| openvpn | openvpn | 2.0_test26 | |
| openvpn | openvpn | 2.0_test27 | |
| openvpn | openvpn | 2.0_test28 | |
| openvpn | openvpn | 2.0_test29 | |
| openvpn | openvpn | 2.1 | |
| openvpn | openvpn | 2.1.0 | |
| openvpn | openvpn | 2.1.1 | |
| openvpn | openvpn | 2.1.2 | |
| openvpn | openvpn | 2.1.3 | |
| openvpn | openvpn | 2.1.4 | |
| openvpn | openvpn | 2.2 | |
| openvpn | openvpn | 2.2.0 | |
| openvpn | openvpn | 2.2.1 | |
| openvpn | openvpn | 2.2.2 | |
| openvpn | openvpn | 2.3 | |
| openvpn | openvpn | 2.3.0 | |
| openvpn | openvpn | 2.3.1 | |
| openvpn | openvpn | 2.3.2 | |
| openvpn | openvpn | 2.3.3 | |
| openvpn | openvpn | 2.3.4 | |
| openvpn | openvpn | 2.3.5 | |
| openvpn | openvpn_access_server | 2.0.0 | |
| openvpn | openvpn_access_server | 2.0.1 | |
| openvpn | openvpn_access_server | 2.0.2 | |
| openvpn | openvpn_access_server | 2.0.3 | |
| openvpn | openvpn_access_server | 2.0.5 | |
| openvpn | openvpn_access_server | 2.0.6 | |
| openvpn | openvpn_access_server | 2.0.7 | |
| openvpn | openvpn_access_server | 2.0.8 | |
| openvpn | openvpn_access_server | 2.0.10 | |
References
- http://advisories.mageia.org/MGASA-2014-0512.html
- http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00008.html
- http://www.debian.org/security/2014/dsa-3084
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:139
- http://www.ubuntu.com/usn/USN-2430-1
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-97597e732b
- https://security-tracker.debian.org/tracker/CVE-2014-8104
CWEs
CWE-399
Verify integrity in audit chain (admin only). AS-IS.