Описание
Security update for openvpn
This update for openvpn fixes the following issues:
- CVE-2024-28882: Fix multiple exit notifications from authenticated clients will extend the validity of a closing session (bsc#1227546)
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP6
openvpn-2.6.8-150600.3.3.1
openvpn-auth-pam-plugin-2.6.8-150600.3.3.1
openvpn-devel-2.6.8-150600.3.3.1
openSUSE Leap 15.6
openvpn-2.6.8-150600.3.3.1
openvpn-auth-pam-plugin-2.6.8-150600.3.3.1
openvpn-devel-2.6.8-150600.3.3.1
openvpn-down-root-plugin-2.6.8-150600.3.3.1
Ссылки
- Link for SUSE-SU-2024:3502-1
- E-Mail link for SUSE-SU-2024:3502-1
- SUSE Security Ratings
- SUSE Bug 1227546
- SUSE CVE CVE-2024-28882 page
Описание
OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:openvpn-2.6.8-150600.3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:openvpn-auth-pam-plugin-2.6.8-150600.3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:openvpn-devel-2.6.8-150600.3.3.1
openSUSE Leap 15.6:openvpn-2.6.8-150600.3.3.1
Ссылки
- CVE-2024-28882
- SUSE Bug 1227546