SB2017080702 - Ubuntu update for OpenVPN
Published: August 7, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) MitM attack (CVE-ID: CVE-2017-7520)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack or obtain potentially sensitive client's information.
If clients use a HTTP proxy with NTLM authentication (i.e. "--http-proxy <server> <port> [<authfile>|'auto'|'auto-nct'] ntlm2"), a man-in-the-middle attacker between the client and the proxy can cause the client to crash or disclose at most 96 bytes of stack memory. The disclosed stack memory is likely to contain the proxy password.
Remediation
Install update from vendor's website.