Fedora Account System
Red Hat Associate
Red Hat Customer
OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service. https://openvpn.net/security-advisory/access-server-security-update-cve-2020-15077-cve-2020-36382/ https://openvpn.net/vpn-server-resources/release-notes/
Created openvpn tracking bugs for this issue: Affects: epel-all [bug 1968025] Affects: fedora-all [bug 1968024]
This is not packaged in neither RHEL nor Fedora. OpenVPN ACCESS SERVER is NOT an open source project.
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.