OpenVPN — свободная реализация технологии виртуальной частной сети (VPN) с открытым исходным кодом для создания зашифрованных каналoв типа точка-точка или сервер-клиенты между компьютерами.
Релизный цикл, информация об уязвимостях
График релизов
Количество 203
GHSA-q7pv-xr8p-6j5f
OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.
GHSA-gj66-3prg-44gq
Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.
GHSA-86x4-whvc-8cfg
OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.
GHSA-h572-qc5h-fc64
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.
SUSE-SU-2022:14937-1
Security update for openvpn-openssl1
SUSE-SU-2022:1029-1
Security update for openvpn
openSUSE-SU-2022:1029-1
Security update for openvpn
SUSE-SU-2022:1024-1
Security update for openvpn
BDU:2022-01642
Уязвимость программного обеспечения OpenVPN, связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти процесс аутентификации и получить доступ к конфиденциальной информации
GHSA-g28r-w65r-h89m
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-q7pv-xr8p-6j5f OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses. | 0% Низкий | почти 4 года назад | ||
GHSA-gj66-3prg-44gq Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate. | 1% Низкий | почти 4 года назад | ||
GHSA-86x4-whvc-8cfg OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted. | 1% Низкий | почти 4 года назад | ||
GHSA-h572-qc5h-fc64 OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts. | 1% Низкий | почти 4 года назад | ||
SUSE-SU-2022:14937-1 Security update for openvpn-openssl1 | 1% Низкий | почти 4 года назад | ||
SUSE-SU-2022:1029-1 Security update for openvpn | 1% Низкий | почти 4 года назад | ||
openSUSE-SU-2022:1029-1 Security update for openvpn | 1% Низкий | почти 4 года назад | ||
SUSE-SU-2022:1024-1 Security update for openvpn | 1% Низкий | почти 4 года назад | ||
BDU:2022-01642 Уязвимость программного обеспечения OpenVPN, связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти процесс аутентификации и получить доступ к конфиденциальной информации | CVSS3: 4.8 | 1% Низкий | почти 4 года назад | |
GHSA-g28r-w65r-h89m OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу