New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 726674 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 774436
Owner:
Last visit > 30 days ago
Closed: Feb 2018
Cc:
EstimatedDays: ----
NextAction: 2017-06-07
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in net-vpn/openvpn

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, May 26 2017

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: net-vpn/openvpn
Package Version: [cpe:/a:openvpn:openvpn:2.4.1 cpe:/a:openvpn:openvpn:2.4.2]

Advisory: CVE-2017-7478
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-7478
  CVSS severity score: 5/10.0
  Confidence: high
  Description:

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
Advisory: CVE-2017-7479
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-7479
  CVSS severity score: 4/10.0
  Confidence: high
  Description:

OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.


 

Comment 1 by kenrb@chromium.org, May 26 2017

Cc: jorgelo@chromium.org
Owner: vapier@chromium.org
Status: Assigned (was: Untriaged)
I'm not sure who the best person to comment on this is, please reassign if you have a better idea than me.

I'm guessing this is a WontFix, because I don't think OpenVPN on ChromeOS would ever accept incoming requests, and both of these CVEs refer to server DoS. Can anybody confirm or contradict that?
Labels: M-62 Security_Impact-None
NextAction: 2017-06-07
I think Ken's analysis is accurate. I'm gonna keep this open because we're trying to update our packages more often, but 
... but this is Impact-None.
The NextAction date has arrived: 2017-06-07
Cc: briannorris@chromium.org cernekee@chromium.org vapier@chromium.org kirtika@chromium.org
Owner: cernekee@chromium.org
Mergedinto: 774436
Status: Duplicate (was: Assigned)
We should be on 2.4.4 now.
Project Member

Comment 7 by sheriffbot@chromium.org, May 19 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment