Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:1053-2

Опубликовано: 01 апр. 2025
Источник: suse-cvrf

Описание

Security update for openvpn

This update for openvpn fixes the following issues:

  • CVE-2024-5594: Fixed handling of null bytes and invalid characters in control messages (bsc#1235147).

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
openvpn-2.3.8-16.35.1
openvpn-auth-pam-plugin-2.3.8-16.35.1

Описание

OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:openvpn-2.3.8-16.35.1
SUSE Linux Enterprise Server 12 SP5-LTSS:openvpn-auth-pam-plugin-2.3.8-16.35.1

Ссылки