After multiple audits in May, 4 important security vulnerabilities discovered in OpenVPN

Elixer

Lifer
May 7, 2002
10,371
762
126
About that audit that was just done in May... Whoops!

I’ve discovered 4 important security vulnerabilities in OpenVPN. Interestingly, these were not found by the two recently completed audits of OpenVPN code. Below you’ll find mostly technical information about the vulnerabilities and about how I found them, but also some commentary on why commissioning code audits isn’t always the best way to find vulnerabilities.

https://guidovranken.wordpress.com/2017/06/21/the-openvpn-post-audit-bug-bonanza/