Family: Debian Local Security Checks --> Category: infos
[DSA885] DSA-885-1 openvpn Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
Several vulnerabilities have been discovered in OpenVPN, a free
virtual private network daemon. The Common Vulnerabilities and
Exposures project identifies the following problems:
A format string vulnerability has been discovered that could allow
arbitrary code to be executed on the client.
A NULL pointer dereferencing has been discovered that could be
exploited to crash the service.
The old stable distribution (woody) does not contain openvpn packages.
For the stable distribution (sarge) these problems have been fixed in
For the unstable distribution (sid) these problems have been fixed in
We recommend that you upgrade your openvpn package.
Solution : http://www.debian.org/security/2005/dsa-885
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.