CVE-2014-8104
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
6.8
Description
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
SUSE Affected 3 releases
| Version | Status | Fixed in |
|---|---|---|
| 13.2 | Affected | โ |
| 13.1 | Affected | โ |
| 12.3 | Affected | โ |
Ubuntu Affected 3 releases
| Version | Status | Fixed in |
|---|---|---|
| 14.10 | Affected | โ |
| 14.04 | Affected | โ |
| 12.04 | Affected | โ |
Debian Mixed 7 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.3.4-5 |
| sid | Fixed | 2.3.4-5 |
| forky | Fixed | 2.3.4-5 |
| bullseye | Fixed | 2.3.4-5 |
| bookworm | Fixed | 2.3.4-5 |
| 8.0 | Affected | โ |
| 7.0 | Affected | โ |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openvpn | openvpn | 2.0.1_rc1 | |
| openvpn | openvpn | 2.0.1_rc2 | |
| openvpn | openvpn | 2.0.1_rc3 | |
| openvpn | openvpn | 2.0.1_rc4 | |
| openvpn | openvpn | 2.0.1_rc5 | |
| openvpn | openvpn | 2.0.1_rc6 | |
| openvpn | openvpn | 2.0.1_rc7 | |
| openvpn | openvpn | 2.0.2_rc1 | |
| openvpn | openvpn | 2.0.3_rc1 | |
| openvpn | openvpn | 2.0.4 | |
| openvpn | openvpn | 2.0.6_rc1 | |
| openvpn | openvpn | 2.0.9 | |
| openvpn | openvpn | 2.0_rc1 | |
| openvpn | openvpn | 2.0_rc2 | |
| openvpn | openvpn | 2.0_rc3 | |
| openvpn | openvpn | 2.0_rc4 | |
| openvpn | openvpn | 2.0_rc5 | |
| openvpn | openvpn | 2.0_rc6 | |
| openvpn | openvpn | 2.0_rc7 | |
| openvpn | openvpn | 2.0_rc8 | |
| openvpn | openvpn | 2.0_rc9 | |
| openvpn | openvpn | 2.0_rc10 | |
| openvpn | openvpn | 2.0_rc11 | |
| openvpn | openvpn | 2.0_rc12 | |
| openvpn | openvpn | 2.0_rc13 | |
| openvpn | openvpn | 2.0_rc14 | |
| openvpn | openvpn | 2.0_rc15 | |
| openvpn | openvpn | 2.0_rc16 | |
| openvpn | openvpn | 2.0_rc17 | |
| openvpn | openvpn | 2.0_rc18 | |
| openvpn | openvpn | 2.0_rc19 | |
| openvpn | openvpn | 2.0_rc20 | |
| openvpn | openvpn | 2.0_rc21 | |
| openvpn | openvpn | 2.0_test1 | |
| openvpn | openvpn | 2.0_test2 | |
| openvpn | openvpn | 2.0_test3 | |
| openvpn | openvpn | 2.0_test4 | |
| openvpn | openvpn | 2.0_test5 | |
| openvpn | openvpn | 2.0_test6 | |
| openvpn | openvpn | 2.0_test7 | |
| openvpn | openvpn | 2.0_test8 | |
| openvpn | openvpn | 2.0_test9 | |
| openvpn | openvpn | 2.0_test10 | |
| openvpn | openvpn | 2.0_test11 | |
| openvpn | openvpn | 2.0_test12 | |
| openvpn | openvpn | 2.0_test14 | |
| openvpn | openvpn | 2.0_test15 | |
| openvpn | openvpn | 2.0_test16 | |
| openvpn | openvpn | 2.0_test17 | |
| openvpn | openvpn | 2.0_test18 | |
| openvpn | openvpn | 2.0_test19 | |
| openvpn | openvpn | 2.0_test20 | |
| openvpn | openvpn | 2.0_test21 | |
| openvpn | openvpn | 2.0_test22 | |
| openvpn | openvpn | 2.0_test23 | |
| openvpn | openvpn | 2.0_test24 | |
| openvpn | openvpn | 2.0_test25 | |
| openvpn | openvpn | 2.0_test26 | |
| openvpn | openvpn | 2.0_test27 | |
| openvpn | openvpn | 2.0_test28 | |
| openvpn | openvpn | 2.0_test29 | |
| openvpn | openvpn | 2.1 | |
| openvpn | openvpn | 2.1.0 | |
| openvpn | openvpn | 2.1.1 | |
| openvpn | openvpn | 2.1.2 | |
| openvpn | openvpn | 2.1.3 | |
| openvpn | openvpn | 2.1.4 | |
| openvpn | openvpn | 2.2 | |
| openvpn | openvpn | 2.2.0 | |
| openvpn | openvpn | 2.2.1 | |
| openvpn | openvpn | 2.2.2 | |
| openvpn | openvpn | 2.3 | |
| openvpn | openvpn | 2.3.0 | |
| openvpn | openvpn | 2.3.1 | |
| openvpn | openvpn | 2.3.2 | |
| openvpn | openvpn | 2.3.3 | |
| openvpn | openvpn | 2.3.4 | |
| openvpn | openvpn | 2.3.5 | |
| openvpn | openvpn_access_server | 2.0.0 | |
| openvpn | openvpn_access_server | 2.0.1 | |
| openvpn | openvpn_access_server | 2.0.2 | |
| openvpn | openvpn_access_server | 2.0.3 | |
| openvpn | openvpn_access_server | 2.0.5 | |
| openvpn | openvpn_access_server | 2.0.6 | |
| openvpn | openvpn_access_server | 2.0.7 | |
| openvpn | openvpn_access_server | 2.0.8 | |
| openvpn | openvpn_access_server | 2.0.10 | |
References
- http://advisories.mageia.org/MGASA-2014-0512.html
- http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00008.html
- http://www.debian.org/security/2014/dsa-3084
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:139
- http://www.ubuntu.com/usn/USN-2430-1
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-97597e732b
- https://security-tracker.debian.org/tracker/CVE-2014-8104
CWEs
CWE-399
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.