First published: Tue Jan 31 2017(Updated: )
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openvpn Openvpn | <=2.3.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.