USN-5347-1: OpenVPN vulnerability
It was discovered that OpenVPN incorrectly handled certain configurations with multiple authentication plugins. A remote attacker could possibly use this issue to bypass authentication using incomplete credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-5347-1?
The vulnerability USN-5347-1 is classified as a moderate severity issue that allows bypassing authentication under specific configurations.
How do I fix USN-5347-1?
To fix USN-5347-1, you should upgrade to the patched versions of OpenVPN: 2.5.1-3ubuntu1.1 for Ubuntu 21.10, 2.4.7-1ubuntu2.20.04.4 for Ubuntu 20.04, or 2.4.4-2ubuntu1.7 for Ubuntu 18.04.
What components are affected by USN-5347-1?
USN-5347-1 affects OpenVPN versions prior to the specified patched releases in various Ubuntu versions.
Can USN-5347-1 be exploited remotely?
Yes, a remote attacker could potentially exploit USN-5347-1 to bypass authentication using incomplete credentials.
What are the potential consequences of USN-5347-1?
The consequences of USN-5347-1 may include unauthorized access to VPN services due to authentication bypass.