CVE-2013-2061
Currently unrated
Key Information:
- Vendor
- Openvpn
- Vendor
- CVE Published:
- 18 November 2013
Summary
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
References
Timeline
Vulnerability published
Vulnerability Reserved