USN-4933-1: OpenVPN vulnerabilities
It was discovered that OpenVPN incorrectly handled certain data channel v2 packets. A remote attacker could possibly use this issue to inject packets using a victim's peer-id. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-11810) It was discovered that OpenVPN incorrectly handled deferred authentication. When a server is configured to use deferred authentication, a remote attacker could possibly use this issue to bypass authentication and access control channel data. (CVE-2020-15078)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this OpenVPN vulnerability?
The vulnerability ID for this OpenVPN vulnerability is CVE-2020-11810.
Which versions of Ubuntu are affected by this OpenVPN vulnerability?
This OpenVPN vulnerability affects Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
How can a remote attacker exploit this OpenVPN vulnerability?
A remote attacker could potentially exploit this OpenVPN vulnerability by injecting packets using a victim's peer-id.
What is the recommended version of OpenVPN to fix this vulnerability on Ubuntu 18.04 LTS?
The recommended version of OpenVPN to fix this vulnerability on Ubuntu 18.04 LTS is 2.4.4-2ubuntu1.5 or later.
Where can I find more information about this OpenVPN vulnerability?
You can find more information about this OpenVPN vulnerability at the following references: [CVE-2020-15078](https://ubuntu.com/security/CVE-2020-15078) and [CVE-2020-11810](https://ubuntu.com/security/CVE-2020-11810).