| Headlines |
| 2019-12-09 |
VPN hijacking vulnerability on Linux and BSD systems |
 |
As reported by Linux Weekly News and other media, a serious vulnerability affecting VPN users on Linux has been discovered by William J. Tolley. The author notes that most Linux distributions are vulnerable, especially those that "use a version of systemd pulled after November 28th of last year which turned reverse path filtering off.". The report, which was assigned a CVE number CVE-2019-14899, reads: "We have discovered a vulnerability in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android which allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel. This vulnerability works against OpenVPN, WireGuard, and IKEv2/IPSec, but has not been thoroughly tested against tor, but we believe it is not vulnerable since it operates in a SOCKS layer and includes authentication and encryption that happens in userspace." The report also provides a list of distributions affected by this vulnerability, including Ubuntu, Fedora, Debian, Arch Linux, Manjaro Linux, Devuan, MX Linux, Void Linux, Slackware Linux, Deepin, FreeBSD and OpenBSD.
|
More headlines from this project
Back to News
|
|
| TUXEDO |

TUXEDO Computers - Linux Hardware in a tailor made suite Choose from a wide range of laptops and PCs in various sizes and shapes at TUXEDOComputers.com. Every machine comes pre-installed and ready-to-run with Linux. Full 24 months of warranty and lifetime support included!
Learn more about our full service package and all benefits from buying at TUXEDO.
|
| Star Labs |

Star Labs - Laptops built for Linux.
View our range including the highly anticipated StarFighter. Available with coreboot open-source firmware and a choice of Ubuntu, elementary, Manjaro and more. Visit Star Labs for information, to buy and get support.
|
|