File _patchinfo of Package patchinfo.4886

<patchinfo incident="4886">
  <issue id="995374" tracker="bnc">VUL-0: CVE-2016-6329: openvpn: affected by 64bit cipher birthday attack (SWEET32)</issue>
  <issue id="1038709" tracker="bnc">VUL-0: CVE-2017-7478: openvpn: Authenticated user can DoS server by using a big payload in P_CONTROL</issue>
  <issue id="1038711" tracker="bnc">VUL-0: CVE-2017-7479: openvpn: Denial of Service due to Exhaustion of Packet-ID counter</issue>
  <issue id="1038713" tracker="bnc">VUL-1: openvpn: Include hardening measures found by audit</issue>
  <issue id="2017-7478" tracker="cve" />
  <issue id="2017-7479" tracker="cve" />
  <issue id="2016-6329" tracker="cve" />
  <category>security</category>
  <rating>important</rating>
  <packager>ndas</packager>
  <description>This update for openvpn fixes the following issues:

- CVE-2016-6329: Show which ciphers should no longer be used in openvpn --show-ciphers (bsc#995374)
- CVE-2017-7478: openvpn: Authenticated user can DoS server by using a big payload in P_CONTROL (bsc#1038709)
- CVE-2017-7479: openvpn: Denial of Service due to Exhaustion of Packet-ID counter (bsc#1038711)
- Hardening measures found by internal audit (bsc#1038713)


</description>
  <summary>Security update for openvpn</summary>
</patchinfo>
openSUSE Build Service is sponsored by