Lucene search

K
osvGoogleOSV:USN-6860-1
HistoryJul 02, 2024 - 1:44 p.m.

openvpn vulnerabilities

2024-07-0213:44:50
Google
osv.dev
1
openvpn
vulnerabilities
reynir björnsson
ubuntu
denial of service
control channel
remote authentication

6.8 Medium

AI Score

Confidence

Low

Reynir Björnsson discovered that OpenVPN incorrectly handled terminating
client connections. A remote authenticated client could possibly use this
issue to keep the connection active, bypassing certain security policies.
This issue only affected Ubuntu 23.10, and Ubuntu 24.04 LTS.
(CVE-2024-28882)

Reynir Björnsson discovered that OpenVPN incorrectly handled certain
control channel messages with nonprintable characters. A remote attacker
could possibly use this issue to cause OpenVPN to consume resources, or
fill up log files with garbage, leading to a denial of service.
(CVE-2024-5594)

6.8 Medium

AI Score

Confidence

Low