The OpenVPN project reports:
OpenVPN 2.3.0 and earlier running in UDP mode are subject to chosen ciphertext injection due to a non-constant-time HMAC comparison function. [source]
OpenVPN 2.3.0 and earlier running in UDP mode are subject to chosen ciphertext injection due to a non-constant-time HMAC comparison function.
Copyright © 2003-2005 Jacques Vidrine and contributors. Please see the source of this document for full copyright information.