CVE-2013-2061
18.11.2013, 02:55
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.Enginsight
Vendor | Product | Version |
---|---|---|
openvpn | openvpn | 𝑥 ≤ 2.3.0 |
openvpn | openvpn | 1.2.0 |
openvpn | openvpn | 1.2.1 |
openvpn | openvpn | 1.3.0 |
openvpn | openvpn | 1.3.1 |
openvpn | openvpn | 1.3.2 |
openvpn | openvpn | 1.4.0 |
openvpn | openvpn | 1.4.1 |
openvpn | openvpn | 1.4.2 |
openvpn | openvpn | 1.4.3 |
openvpn | openvpn | 1.5.0 |
openvpn | openvpn | 1.6.0 |
openvpn | openvpn | 2.1.0 |
openvpn | openvpn | 2.2.0 |
openvpn | openvpn_access_server | 2.0.0 |
opensuse | opensuse | 11.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References