Lucene search

K
ubuntuUbuntuUSN-6860-1
HistoryJul 02, 2024 - 12:00 a.m.

OpenVPN vulnerabilities

2024-07-0200:00:00
ubuntu.com
openvpn
ubuntu
vulnerabilities
remote authenticated client
security policies
control channel messages
denial of service

7.3 High

AI Score

Confidence

Low

Releases

  • Ubuntu 24.04 LTS
  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • openvpn - virtual private network software

Details

Reynir Björnsson discovered that OpenVPN incorrectly handled terminating
client connections. A remote authenticated client could possibly use this
issue to keep the connection active, bypassing certain security policies.
This issue only affected Ubuntu 23.10, and Ubuntu 24.04 LTS.
(CVE-2024-28882)

Reynir Björnsson discovered that OpenVPN incorrectly handled certain
control channel messages with nonprintable characters. A remote attacker
could possibly use this issue to cause OpenVPN to consume resources, or
fill up log files with garbage, leading to a denial of service.
(CVE-2024-5594)

OSVersionArchitecturePackageVersionFilename
Ubuntu24.04noarchopenvpn< 2.6.9-1ubuntu4.1UNKNOWN
Ubuntu24.04noarchopenvpn-dbgsym< 2.6.9-1ubuntu4.1UNKNOWN
Ubuntu23.10noarchopenvpn< 2.6.5-0ubuntu1.2UNKNOWN
Ubuntu23.10noarchopenvpn-dbgsym< 2.6.5-0ubuntu1.2UNKNOWN
Ubuntu22.04noarchopenvpn< 2.5.9-0ubuntu0.22.04.3UNKNOWN
Ubuntu22.04noarchopenvpn-dbgsym< 2.5.9-0ubuntu0.22.04.3UNKNOWN
Ubuntu20.04noarchopenvpn< 2.4.12-0ubuntu0.20.04.2UNKNOWN
Ubuntu20.04noarchopenvpn-dbgsym< 2.4.12-0ubuntu0.20.04.2UNKNOWN