OpenVPN: Authentication bypass — GLSA 202105-25

A vulnerability has been found in OpenVPN, allowing attackers to bypass the authentication process.

Affected packages

net-vpn/openvpn on all architectures
Affected versions < 2.5.2
Unaffected versions >= 2.5.2

Background

OpenVPN is a multi-platform, full-featured SSL VPN solution.

Description

It was discovered that OpenVPN incorrectly handled deferred authentication.

Impact

A remote attacker could bypass authentication and access control channel data and trigger further information leaks.

Workaround

Configure OpenVPN server to not use deferred authentication.

Resolution

All OpenVPN users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-vpn/openvpn-2.5.2"
 

References

Release date
May 26, 2021

Latest revision
May 26, 2021: 1

Severity
normal

Exploitable
remote

Bugzilla entries