{
  "schema_version": "1.7.0",
  "id": "MGASA-2016-0010",
  "published": "2016-01-12T09:13:53Z",
  "modified": "2016-01-12T08:56:27Z",
  "summary": "Updated openvpn packages fix security vulnerability",
  "details": "OpenVPN versions before 2.3.9 contain an out of bounds read error in\nresolve_remote() in the file socket.c.  With both IPv4 and IPv6\nconnections, OpenVPN will read a struct sockaddr_in6, but in the IPv4 case\nthe data structure is smaller than in the IPv6 case.\n\nThe openvpn package has been updated to version 2.3.9, fixing this issue\nand several other bugs.  See the upstream Changelog for details.\n",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2016-0010.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=17418"
    },
    {
      "type": "WEB",
      "url": "https://blog.fuzzing-project.org/32-Out-of-bounds-read-in-OpenVPN.html"
    },
    {
      "type": "WEB",
      "url": "https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn23#OpenVPN2.3.9"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:5",
        "name": "openvpn",
        "purl": "pkg:rpm/mageia/openvpn?arch=source&distro=mageia-5"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.3.9-1.mga5"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
