Back to Database
Status published
Medium
CVE-2014-8104
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x...
Vulnerability Description
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-8104
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:139
- http://advisories.mageia.org/MGASA-2014-0512.html
- http://www.ubuntu.com/usn/USN-2430-1
- http://www.debian.org/security/2014/dsa-3084
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-97597e732b
- http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00008.html
More from mageia
View All →CVE-2015-0236
libvirt before 1.2.12 allow remote authenticated users to obtain the...
Low
3.5
CVE-2014-9087
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2,...
High
7.5
CVE-2014-8136
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in...
Low
2.1
CVE-2014-2524
The _rl_tropen function in util.c in GNU readline before 6.3...
Low
3.3
Affected Vendor
mageia
View all reports →Affected Software
mageia, debian linux, opensuse, openvpn, openvpn access server, ubuntu linux
Vulnerable Versions:
4.0, 7.0, 8.0, 12.3, 13.1, 13.2, 2.0.1_rc1, 2.0.1_rc2, 2.0.1_rc3, 2.0.1_rc4, 2.0.1_rc5, 2.0.1_rc6, 2.0.1_rc7, 2.0.2_rc1, 2.0.3_rc1, 2.0.4, 2.0.6_rc1, 2.0.9, 2.0_rc1, 2.0_rc2, 2.0_rc3, 2.0_rc4, 2.0_rc5, 2.0_rc6, 2.0_rc7, 2.0_rc8, 2.0_rc9, 2.0_rc10, 2.0_rc11, 2.0_rc12, 2.0_rc13, 2.0_rc14, 2.0_rc15, 2.0_rc16, 2.0_rc17, 2.0_rc18, 2.0_rc19, 2.0_rc20, 2.0_rc21, 2.0_test1, 2.0_test2, 2.0_test3, 2.0_test4, 2.0_test5, 2.0_test6, 2.0_test7, 2.0_test8, 2.0_test9, 2.0_test10, 2.0_test11, 2.0_test12, 2.0_test14, 2.0_test15, 2.0_test16, 2.0_test17, 2.0_test18, 2.0_test19, 2.0_test20, 2.0_test21, 2.0_test22, 2.0_test23, 2.0_test24, 2.0_test25, 2.0_test26, 2.0_test27, 2.0_test28, 2.0_test29, 2.1, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.2, 2.2.0, 2.2.1, 2.2.2, 2.3, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.10, 12.04, 14.04, 14.10
Timeline
Official Publish:
December 3rd, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.