Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 918673 (CVE-2020-20813)

Summary: net-vpn/openvpn: DoS via crafted reset packet
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: minor CC: chutzpah, hydrapolic, williamh
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.freebuf.com/vuls/215171.html
Whiteboard: B3 [upstream]
Package list:
Runtime testing required: ---

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-27 19:36:45 UTC
CVE-2020-20813:

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

Advisory is only in Chinese but seems to translate well with Google
Translate. It seems to be documenting some kind of DDoS amplification
which involved OpenVPN but it's not actually clear to me based on that
whether this is a real vulnerability in OpenVPN or some kind of
misconfiguration.