Описание
Security update for openvpn
This update for openvpn fixes the following issues:
- CVE-2024-5594: Fixed handling of null bytes and invalid characters in control messages (bsc#1235147).
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
openvpn-2.3.8-16.35.1
openvpn-auth-pam-plugin-2.3.8-16.35.1
Ссылки
- Link for SUSE-SU-2025:1053-2
- E-Mail link for SUSE-SU-2025:1053-2
- SUSE Security Ratings
- SUSE Bug 1235147
- SUSE CVE CVE-2024-5594 page
Описание
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:openvpn-2.3.8-16.35.1
SUSE Linux Enterprise Server 12 SP5-LTSS:openvpn-auth-pam-plugin-2.3.8-16.35.1
Ссылки
- CVE-2024-5594
- SUSE Bug 1235147