CVE-2024-5594
06.01.2025, 14:15
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openvpn | openvpn | 2.6.0 ≤ 𝑥 < 2.6.11 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| openvpn |
|
Common Weakness Enumeration