cbcvebase.

Debian Openvpn vulnerabilities

27 known vulnerabilities affecting debian/openvpn.

Total CVEs
27
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH10MEDIUM6LOW7

Vulnerabilities

Page 2 of 2
CVE-2025-15497P4LOWCVSS 3.8fixed in openvpn 2.7.0~rc5-1 (forky)2025
CVE-2025-15497 [LOW] CVE-2025-15497: openvpn - Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 all... Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 2.7.0~rc5-1) sid: resolved (fixed in 2.7.0~rc5-1) trixie: resolved
debian
CVE-2005-2532P4HIGHCVSS 5.0fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2532 [MEDIUM] CVE-2005-2532: openvpn - OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a pack... OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted. Scope: local bookworm: resolved (fixed in 2.0.2-1) bullseye: resolved (fixed in 2.0.2-1) forky:
debian
CVE-2005-3409P4LOWCVSS 5.0fixed in openvpn 2.0.5-1 (bookworm)2005
CVE-2005-3409 [MEDIUM] CVE-2005-3409: openvpn - OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to c... OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler. Scope: local bookworm: resolved (fixed in 2.0.5-1) bullseye: resolved (fixed in 2.0.5-1) forky: resolved (fixed in 2.0.5
debian
CVE-2020-11810P4LOWCVSS 3.7fixed in openvpn 2.4.9-1 (bookworm)2020
CVE-2020-11810 [LOW] CVE-2020-11810: openvpn - An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a ... An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (u
debian
CVE-2013-2061P4LOWCVSS 2.6fixed in openvpn 2.3.1-1 (bookworm)2013
CVE-2013-2061 [LOW] CVE-2013-2061: openvpn - The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when runn... The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher. Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fi
debian
CVE-2005-2534P4HIGHCVSS 2.6fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2534 [LOW] CVE-2005-2534: openvpn - Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allo... Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate. Scope: local bookworm: resolved (fixed in 2.0.2-1) bullseye: resolved (fixed in 2.0.2-1) forky: resolved (fixed in 2.0.2-1) sid: resol
debian
CVE-2005-2533P4HIGHCVSS 2.1fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2533 [LOW] CVE-2005-2533: openvpn - OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows r... OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses. Scope: local bookworm: resolved (fixed in 2.0.2-1) bullseye: resolved (fixed in 2.0.2-1) forky: resolved (fixed in 2.0.2-1) sid: resolved (fixed
debian
Debian Openvpn vulnerabilities | cvebase