Back to search
CVE-2013-2061
Published: Nov 15, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2013-7552
vendor-advisory
x_refsource_FEDORA
FEDORA-2013-7531
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2013:1645
vendor-advisory
x_refsource_SUSE
https://bugzilla.redhat.com/show_bug.cgi?id=960192
x_refsource_CONFIRM
MDVSA-2013:167
vendor-advisory
x_refsource_MANDRIVA
openSUSE-SU-2013:1649
vendor-advisory
x_refsource_SUSE
https://bugs.gentoo.org/show_bug.cgi?id=468756
x_refsource_CONFIRM
https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-f375aa67cc
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now