cbcvebase.

Debian Openvpn vulnerabilities

27 known vulnerabilities affecting debian/openvpn.

Total CVEs
27
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH10MEDIUM6LOW7

Vulnerabilities

Page 1 of 2
CVE-2017-7478P3HIGHCVSS 7.5PoCfixed in openvpn 2.4.0-5 (bookworm)2017
CVE-2017-7478 [HIGH] CVE-2017-7478: openvpn - OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Serv... OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2. Scope: local bookworm: resolved (fixed in 2.4.0-5) bullseye: resolved (fixed in 2.4.0-5) forky: resolved (fixed in 2.4.0-5) sid: resolved (fixed in 2.4.0-5) trixie: resolved (fixed in 2.4.0-
debian
CVE-2022-0547P2CRITICALCVSS 9.8fixed in openvpn 2.5.6-1 (bookworm)2022
CVE-2022-0547 [CRITICAL] CVE-2022-0547: openvpn - OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in externa... OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials. Scope: local bookworm: resolved (fixed in 2.5.6-1) bullseye: resolved (fixed in 2.5.1-3+deb11u1
debian
CVE-2023-46850P3CRITICALCVSS 9.8fixed in openvpn 2.6.3-1+deb12u2 (bookworm)2023
CVE-2023-46850 [CRITICAL] CVE-2023-46850: openvpn - Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir,... Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer. Scope: local bookworm: resolved (fixed in 2.6.3-1+deb12u2) bullseye: resolved forky: resolved (fixed in 2.6.7-1) sid: resolved (fixed in 2.6.7-1) trixie: resolved (fixed in 2.6.7-1)
debian
CVE-2024-5594P3CRITICALCVSS 9.1fixed in openvpn 2.6.3-1+deb12u3 (bookworm)2024
CVE-2024-5594 [CRITICAL] CVE-2024-5594: openvpn - OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an att... OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs. Scope: local bookworm: resolved (fixed in 2.6.3-1+deb12u3) bullseye: resolved (fixed in 2.5.1-3+deb11u1) forky: resolved (fixed in 2.6.11-1) sid: resolved (fixed in 2.6.11-1) trixie: reso
debian
CVE-2020-15078P3HIGHCVSS 7.5fixed in openvpn 2.5.1-2 (bookworm)2020
CVE-2020-15078 [HIGH] CVE-2020-15078: openvpn - OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentic... OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks. Scope: local bookworm: resolved (fixed in 2.5.1-2) bullseye: resolved (fixed in 2.5.1-2) forky: resolved (fixed in 2.5.1-2) sid: r
debian
CVE-2017-12166P3CRITICALCVSS 9.8fixed in openvpn 2.4.4-1 (bookworm)2017
CVE-2017-12166 [CRITICAL] CVE-2017-12166: openvpn - OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer ... OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution. Scope: local bookworm: resolved (fixed in 2.4.4-1) bullseye: resolved (fixed in 2.4.4-1) forky: resolved (fixed in 2.4.4-1) sid: resolved (fixed in 2.4.4-1) trixie: resolved (fixed in 2.4.4-1)
debian
CVE-2008-3459P3LOWCVSS 7.6fixed in openvpn 2.1~rc9-1 (bookworm)2008
CVE-2008-3459 [HIGH] CVE-2008-3459: openvpn - Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on... Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters. Scope: local bookworm: resolved (fixed in 2.1~rc9-1) bullseye: resolved (fixed in 2.1~rc9-1) forky: resolved
debian
CVE-2006-1629P3MEDIUMCVSS 9.0fixed in openvpn 2.0.6-1 (bookworm)2006
CVE-2006-1629 [CRITICAL] CVE-2006-1629: openvpn - OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary c... OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable. Scope: local bookworm: resolved (fixed in 2.0.6-1) bullseye: resolved (fixed in 2.0.6-1) forky: resolved (fixed in 2.0.6-1) sid: resolved (fixed in 2.0.6-1) trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2025-2704P3HIGHCVSS 7.5fixed in openvpn 2.6.3-1+deb12u3 (bookworm)2025
CVE-2025-2704 [HIGH] CVE-2025-2704: openvpn - OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows re... OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase Scope: local bookworm: resolved (fixed in 2.6.3-1+deb12u3) bullseye: resolved forky: resolved (fixed in 2.6.14-1) sid: resolved (fixed in 2.6.14-1) trixie: resolved (fixed
debian
CVE-2025-13086P3MEDIUMCVSS 4.6fixed in openvpn 2.6.3-1+deb12u4 (bookworm)2025
CVE-2025-13086 [MEDIUM] CVE-2025-13086: openvpn - Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.... Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client Scope: local bookworm: resolved (fixed in 2.6.3-1+deb12u4) bullseye: resolved forky: reso
debian
CVE-2017-7508P3HIGHCVSS 7.5fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7508 [HIGH] CVE-2017-7508: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-... OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet. Scope: local bookworm: resolved (fixed in 2.4.3-1) bullseye: resolved (fixed in 2.4.3-1) forky: resolved (fixed in 2.4.3-1) sid: resolved (fixed in 2.4.3-1) trixie: resolved (fixed in 2.4.3-1)
debian
CVE-2017-7520P3HIGHCVSS 7.4fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7520 [HIGH] CVE-2017-7520: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-serv... OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker. Scope: local bookworm: resolved (fixed in 2.4.3-1) bullseye: resolved (fixed in 2.4.3-1) forky: resolved (fixed in 2.4.3-1) sid: resolved (fixed in 2.4.3-1) trixie: resolved (fixed in 2.4.3-1)
debian
CVE-2005-3393P3MEDIUMCVSS 7.5fixed in openvpn 2.0.5-1 (bookworm)2005
CVE-2005-3393 [HIGH] CVE-2005-3393: openvpn - Format string vulnerability in the foreign_option function in options.c for Open... Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option. Scope: local bookworm: resolved (fixed in 2.0.5-1) bullseye: resolved (fixed in 2.0.5-1) forky: resolved (fixed in 2.0.5-1) sid: resolved (fixed in 2.0.5-1) t
debian
CVE-2017-7522P4LOWCVSS 6.5fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7522 [MEDIUM] CVE-2017-7522: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-serv... OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character. Scope: local bookworm: resolved (fixed in 2.4.3-1) bullseye: resolved (fixed in 2.4.3-1) forky: resolved (fixed in 2.4.3-1) sid: resolved (fixed in 2.4.3-1) trixie: resolved (fixed in 2.4.3-1)
debian
CVE-2023-46849P4HIGHCVSS 7.5fixed in openvpn 2.6.3-1+deb12u2 (bookworm)2023
CVE-2023-46849 [HIGH] CVE-2023-46849: openvpn - Using the --fragment option in certain configuration setups OpenVPN version 2.6.... Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service. Scope: local bookworm: resolved (fixed in 2.6.3-1+deb12u2) bullseye: resolved forky: resolved (fixed in 2.6.7-1) sid: resolved (fixed in 2.6.7-1) tr
debian
CVE-2017-7479P4LOWCVSS 6.5fixed in openvpn 2.4.0-5 (bookworm)2017
CVE-2017-7479 [MEDIUM] CVE-2017-7479: openvpn - OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable asse... OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker. Scope: local bookworm: resolved (fixed in 2.4.0-5) bullseye: resolved (fixed in 2.4.0-5) forky: resolved (fixed in 2.4.0-5) sid: resolved (fixed in 2.4.0-5) trixie: resolved (fix
debian
CVE-2017-7521P4MEDIUMCVSS 5.9fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7521 [MEDIUM] CVE-2017-7521: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-... OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension(). Scope: local bookworm: resolved (fixed in 2.4.3-1) bullseye: resolved (fixed in 2.4.3-1) forky: resolved (fixed in 2.4.3-1) sid: resolved (fixed in 2.4.3-1) trixie: resolved (fix
debian
CVE-2014-8104P4MEDIUMCVSS 6.8fixed in openvpn 2.3.4-5 (bookworm)2014
CVE-2014-8104 [MEDIUM] CVE-2014-8104: openvpn - OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 all... OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet. Scope: local bookworm: resolved (fixed in 2.3.4-5) bullseye: resolved (fixed in 2.3.4-5) forky: resolved (fixed in 2.3.4-5) sid: resolved (fixed in 2.3.4-5) trixie: resolved (fi
debian
CVE-2005-2531P4HIGHCVSS 5.0fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2531 [MEDIUM] CVE-2005-2531: openvpn - OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication,... OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentic
debian
CVE-2024-28882P4MEDIUMCVSS 4.3fixed in openvpn 2.6.3-1+deb12u3 (bookworm)2024
CVE-2024-28882 [MEDIUM] CVE-2024-28882: openvpn - OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notific... OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session Scope: local bookworm: resolved (fixed in 2.6.3-1+deb12u3) bullseye: resolved forky: resolved (fixed in 2.6.11-1) sid: resolved (fixed in 2.6.11-1) trixie: resolved (fixed in 2.6.11-1)
debian
Debian Openvpn vulnerabilities | cvebase