Amazon Linux 1 Security Advisory: ALAS-2013-201
Advisory Release Date: 2013-06-11 22:47 Pacific
Advisory Updated Date: 2014-09-15 23:12 Pacific
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
Affected Packages:
openvpn
Issue Correction:
Run yum update openvpn to update your system.
i686:
openvpn-2.3.1-1.7.amzn1.i686
openvpn-debuginfo-2.3.1-1.7.amzn1.i686
src:
openvpn-2.3.1-1.7.amzn1.src
x86_64:
openvpn-debuginfo-2.3.1-1.7.amzn1.x86_64
openvpn-2.3.1-1.7.amzn1.x86_64