FlawAtlas
Search the atlas
SUSE-SU-2017:1642-1 Not scored

Security update for openvpn

This update for openvpn fixes the following issues: - It was possible to trigger an assertion by sending a malformed IPv6 packet. That issue could have been abused to remotely shutdown an openvpn server or client, if IPv6 and --mssfix were enabled and if the IPv6 networks used inside the VPN were known. [bsc#1044947, CVE-2017-7508]

Exploit probability Not scored
Published June 21, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Point of Sale 11 SP3 openvpn
SUSE:Linux Enterprise Server 11 SP3-LTSS openvpn
SUSE:Linux Enterprise Server 11 SP3-TERADATA openvpn
SUSE:Linux Enterprise Server 11 SP4 openvpn
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 openvpn

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2017:1642-1

This update for openvpn fixes the following issues: - It was possible to trigger an assertion by sending a malformed IPv6 packet. That issue could have been abused to remotely shutdown an openvpn server or client, if IPv6 and --mssfix were enabled and if the IPv6 networks used inside the VPN were known. [bsc#1044947, CVE-2017-7508]

View original source

05 / REFERENCES

Further evidence