ALT-PU-2024-10963-1
Package openvpn updated to version 2.6.12-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2024-07-09
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2024-28882
OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
References:
Published: 2025-04-03
CVE-2024-4877
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
References:
Published: 2025-01-06
Modified: 2025-04-03
Modified: 2025-04-03
CVE-2024-5594
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
References: