Описание
Security update for openvpn-openssl1
This update for openvpn-openssl1 fixes the following issues:
Security issue fixed:
- CVE-2017-12166: Fix remote buffer overflow (bsc#1060877).
Список пакетов
SUSE Linux Enterprise Server 11-SECURITY
openvpn-openssl1-2.3.2-0.10.3.1
openvpn-openssl1-down-root-plugin-2.3.2-0.10.3.1
Ссылки
- Link for SUSE-SU-2017:3177-1
- E-Mail link for SUSE-SU-2017:3177-1
- SUSE Security Ratings
- SUSE Bug 1060877
- SUSE CVE CVE-2017-12166 page
Описание
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
Затронутые продукты
SUSE Linux Enterprise Server 11-SECURITY:openvpn-openssl1-2.3.2-0.10.3.1
SUSE Linux Enterprise Server 11-SECURITY:openvpn-openssl1-down-root-plugin-2.3.2-0.10.3.1
Ссылки
- CVE-2017-12166
- SUSE Bug 1060877