Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Ubuntu update for openvpn

Secunia Advisory: SA30136  
Release Date: 2008-05-14
Last Update: 2008-06-13

Critical:
Moderately critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Patch

OS:Ubuntu Linux 7.04
Ubuntu Linux 7.10
Ubuntu Linux 8.04


CVE reference:CVE-2008-0166 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Ubuntu has issued an update for openvpn. This fixes a security issue, which can lead to weak cryptographic key material.

For more information:
SA30221

Solution:
Apply updated packages. Please see vendor advisory for further details.

-- Ubuntu 7.04 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...nvpn/openvpn_2.0.9-5ubuntu0.3.diff.gz
Size/MD5:61721 95f9cbc60c026db52ebf698e36832e29
http://security.ubuntu.com/ubuntu/poo.../openvpn/openvpn_2.0.9-5ubuntu0.3.dsc
Size/MD5:641 253b8e4ccbb5e11ba1dba9d37a1265b9
http://security.ubuntu.com/ubuntu/poo...e/o/openvpn/openvpn_2.0.9.orig.tar.gz
Size/MD5: 669076 60745008b90b7dbe25fe8337c550fec6

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...pn/openvpn_2.0.9-5ubuntu0.3_amd64.deb
Size/MD5: 357046 075f4a00b8aff7049b4f23baced068da

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...vpn/openvpn_2.0.9-5ubuntu0.3_i386.deb
Size/MD5: 337798 4fee6672cb6db4d0be228b644d129d29

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo.../openvpn_2.0.9-5ubuntu0.3_powerpc.deb
Size/MD5: 358528 2658d5751bdc4ee25e5bd3d432c4b2bd

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...pn/openvpn_2.0.9-5ubuntu0.3_sparc.deb
Size/MD5: 336722 755f9f120f5014794f8f0cec49d9203b

-- Ubuntu 7.10 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...nvpn/openvpn_2.0.9-8ubuntu0.3.diff.gz
Size/MD5:65179 ae182aa5b68b9f9d4bddd47859cf0ced
http://security.ubuntu.com/ubuntu/poo.../openvpn/openvpn_2.0.9-8ubuntu0.3.dsc
Size/MD5:642 9a58ebc70f0aff036c8e7acc56e83be7
http://security.ubuntu.com/ubuntu/poo...e/o/openvpn/openvpn_2.0.9.orig.tar.gz
Size/MD5: 669076 60745008b90b7dbe25fe8337c550fec6

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...pn/openvpn_2.0.9-8ubuntu0.3_amd64.deb
Size/MD5: 362566 303b259e514cf777b08e7676be5d7ab0

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...vpn/openvpn_2.0.9-8ubuntu0.3_i386.deb
Size/MD5: 342222 73ed9392ce7b00c92e8505dcf3d80f79

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/universe...vpn/openvpn_2.0.9-8ubuntu0.3_lpia.deb
Size/MD5: 343666 581fdfb7e7d9131926fa55570c96edf0

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo.../openvpn_2.0.9-8ubuntu0.3_powerpc.deb
Size/MD5: 363846 b5068afe9083e4fcc963bf4bae298615

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...pn/openvpn_2.0.9-8ubuntu0.3_sparc.deb
Size/MD5: 342108 712cf75f7edb5cc59db0ff5ac969f9bf

-- Ubuntu 8.04 LTS --

Source archives:

http://security.ubuntu.com/ubuntu/poo...pn/openvpn_2.1~rc7-1ubuntu3.3.diff.gz
Size/MD5:36156 527fa8ebcad65f1cbd130703e134361f
http://security.ubuntu.com/ubuntu/poo...penvpn/openvpn_2.1~rc7-1ubuntu3.3.dsc
Size/MD5:646 90f272f803fa6e34cd54422b9eac0064
http://security.ubuntu.com/ubuntu/poo...o/openvpn/openvpn_2.1~rc7.orig.tar.gz
Size/MD5: 786288 dac8b5104b5eb105ba82b2525d371d58

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo.../openvpn_2.1~rc7-1ubuntu3.3_amd64.deb
Size/MD5: 391374 8783a3d6b5be5469fc0a22e7575cfcbb

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...n/openvpn_2.1~rc7-1ubuntu3.3_i386.deb
Size/MD5: 372674 8e9bd7bb9dc9bc0a8538bb5164a627fa

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/o/openvpn/openvpn_2.1~rc7-1ubuntu3.3_lpia.deb
Size/MD5: 371686 1b0ee05b907c04d0ce8606c5fecb9f23

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/o/o...penvpn_2.1~rc7-1ubuntu3.3_powerpc.deb
Size/MD5: 392054 10c3c48b5060c6071c644a5c29b3dd0e

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/o/openvpn/openvpn_2.1~rc7-1ubuntu3.3_sparc.deb
Size/MD5: 369536 ab9b17960fdc3df59c3cfe61f667bca7

Changelog:
2008-05-15: Updated "Solution" section due to regressions. Added link to "Original Advisory" section.
2008-06-13: Updated "Solution" section due to regressions. Added link to "Original Advisory" section.

Original Advisory:
http://www.ubuntu.com/usn/usn-612-3
http://www.ubuntu.com/usn/usn-612-6
http://www.ubuntu.com/usn/usn-612-10

Other References:
SA30221:
http://secunia.com/advisories/30221/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

165 Related Secunia Security Advisories, displaying 10

1. Ubuntu update for php
2. Ubuntu update for dnsmasq
3. Ubuntu update for firefox
4. Ubuntu update for kernel
5. Ubuntu update for bind
6. Ubuntu update for pcre3
7. Ubuntu update for firefox
8. Ubuntu update for openssl
9. Ubuntu update for ruby1.8
10. Ubuntu update for kernel

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
OpenBSD BIND Query Port DNS Cache Poisoning
2.
Red Hat update for kernel
3.
Drupal Session Fixation Vulnerability
4.
Debian update for clamav
5.
Linux Kernel LDT Buffer Size Handling Vulnerability
6.
IPCop update for perl
7.
Debian update for xulrunner
8.
Ubuntu update for php
9.
Apple Safari Cross-Domain Cookie Injection Vulnerability
10.
Red Hat update for thunderbird





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia