Access control error in OpenVPN for Windows - CVE-2016-6329
Published: September 8, 2016 / Updated: September 29, 2017
Vulnerability details
The vulnerability allows attackers to gain access to potentially sensitive information.
The vulnerability exists due to capturing of long duration Blowfish CBC mode encrypted TLS session. Repeated sending of communication protocol with parts of the plaintext helps attackers to reconstruct the secret information.
Successful exploitation of this vulnerability may allow a remote attacker to access potentially sensitive data.
Affected software
Fedora
IBM i
SUSE Linux
Ubuntu
IBM Cloud Pak for Data Scheduling
Dell DataIQ
openvpn
How to mitigate CVE-2016-6329
Dell DataIQ - update to 2.2.2.0
openvpn - addressed in versions 2.3.12-1.el5, 2.3.12-1.el6, 2.3.12-1.el7, 2.3.12-1.fc23, 2.3.12-1.fc24, 2.3.12-1.fc25
External References
Related Security Bulletins
- SUSE Linux update for openvpn
- Ubuntu update for OpenVPN
- Ubuntu update for OpenVPN
- SUSE Linux update for openvpn
- Multiple vulnerabilities in Dell DataIQ
- Multiple vulnerabilities in IBM i
- Fedora 23 update for openvpn
- Fedora EPEL 5 update for openvpn
- Fedora 24 update for openvpn
- Fedora 25 update for openvpn
- Fedora EPEL 6 update for openvpn
- Fedora EPEL 7 update for openvpn
- Multiple vulnerabilities in IBM CloudPak for Data Scheduling Service