Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:1053-1

Опубликовано: 28 мар. 2025
Источник: suse-cvrf

Описание

Security update for openvpn

This update for openvpn fixes the following issues:

  • CVE-2024-5594: Fixed handling of null bytes and invalid characters in control messages (bsc#1235147).

Список пакетов

SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
openvpn-2.3.8-16.35.1
openvpn-auth-pam-plugin-2.3.8-16.35.1

Описание

OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:openvpn-2.3.8-16.35.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:openvpn-auth-pam-plugin-2.3.8-16.35.1

Ссылки