File _patchinfo of Package patchinfo.4886
<patchinfo incident="4886">
<issue id="995374" tracker="bnc">VUL-0: CVE-2016-6329: openvpn: affected by 64bit cipher birthday attack (SWEET32)</issue>
<issue id="1038709" tracker="bnc">VUL-0: CVE-2017-7478: openvpn: Authenticated user can DoS server by using a big payload in P_CONTROL</issue>
<issue id="1038711" tracker="bnc">VUL-0: CVE-2017-7479: openvpn: Denial of Service due to Exhaustion of Packet-ID counter</issue>
<issue id="1038713" tracker="bnc">VUL-1: openvpn: Include hardening measures found by audit</issue>
<issue id="2017-7478" tracker="cve" />
<issue id="2017-7479" tracker="cve" />
<issue id="2016-6329" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>ndas</packager>
<description>This update for openvpn fixes the following issues:
- CVE-2016-6329: Show which ciphers should no longer be used in openvpn --show-ciphers (bsc#995374)
- CVE-2017-7478: openvpn: Authenticated user can DoS server by using a big payload in P_CONTROL (bsc#1038709)
- CVE-2017-7479: openvpn: Denial of Service due to Exhaustion of Packet-ID counter (bsc#1038711)
- Hardening measures found by internal audit (bsc#1038713)
</description>
<summary>Security update for openvpn</summary>
</patchinfo>