ALAS-2013-201


Amazon Linux AMI Security Advisory: ALAS-2013-201
Advisory Release Date: 2014-09-15 23:12 Pacific
Severity: Low
References: CVE-2013-2061 

Issue Overview:

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.


Affected Packages:

openvpn


Issue Correction:
Run yum update openvpn to update your system.

New Packages:
i686:
    openvpn-2.3.1-1.7.amzn1.i686
    openvpn-debuginfo-2.3.1-1.7.amzn1.i686

src:
    openvpn-2.3.1-1.7.amzn1.src

x86_64:
    openvpn-debuginfo-2.3.1-1.7.amzn1.x86_64
    openvpn-2.3.1-1.7.amzn1.x86_64