Debian Openvpn vulnerabilities
36 known vulnerabilities affecting debian/openvpn.
Total CVEs
36
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH10MEDIUM6LOW16
Vulnerabilities
Page 2 of 2
CVE-2017-7520HIGHCVSS 7.4fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7520 [HIGH] CVE-2017-7520: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-serv...
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.
Scope: local
bookworm: resolved (fixed in 2.4.3-1)
bullseye: resolved (fixed in 2.4.3-1)
forky: resolved (fixed in 2.4.3-1)
sid: resolved (fixed in 2.4.3-1)
trixie: resolved (fixed in 2.4.3-1)
debian
CVE-2017-7508HIGHCVSS 7.5fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7508 [HIGH] CVE-2017-7508: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-...
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.
Scope: local
bookworm: resolved (fixed in 2.4.3-1)
bullseye: resolved (fixed in 2.4.3-1)
forky: resolved (fixed in 2.4.3-1)
sid: resolved (fixed in 2.4.3-1)
trixie: resolved (fixed in 2.4.3-1)
debian
CVE-2017-7478HIGHCVSS 7.5PoCfixed in openvpn 2.4.0-5 (bookworm)2017
CVE-2017-7478 [HIGH] CVE-2017-7478: openvpn - OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Serv...
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
Scope: local
bookworm: resolved (fixed in 2.4.0-5)
bullseye: resolved (fixed in 2.4.0-5)
forky: resolved (fixed in 2.4.0-5)
sid: resolved (fixed in 2.4.0-5)
trixie: resolved (fixed in 2.4.0-
debian
CVE-2017-7521MEDIUMCVSS 5.9fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7521 [MEDIUM] CVE-2017-7521: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-...
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().
Scope: local
bookworm: resolved (fixed in 2.4.3-1)
bullseye: resolved (fixed in 2.4.3-1)
forky: resolved (fixed in 2.4.3-1)
sid: resolved (fixed in 2.4.3-1)
trixie: resolved (fix
debian
CVE-2017-7522LOWCVSS 6.5fixed in openvpn 2.4.3-1 (bookworm)2017
CVE-2017-7522 [MEDIUM] CVE-2017-7522: openvpn - OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-serv...
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
Scope: local
bookworm: resolved (fixed in 2.4.3-1)
bullseye: resolved (fixed in 2.4.3-1)
forky: resolved (fixed in 2.4.3-1)
sid: resolved (fixed in 2.4.3-1)
trixie: resolved (fixed in 2.4.3-1)
debian
CVE-2017-7479LOWCVSS 6.5fixed in openvpn 2.4.0-5 (bookworm)2017
CVE-2017-7479 [MEDIUM] CVE-2017-7479: openvpn - OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable asse...
OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
Scope: local
bookworm: resolved (fixed in 2.4.0-5)
bullseye: resolved (fixed in 2.4.0-5)
forky: resolved (fixed in 2.4.0-5)
sid: resolved (fixed in 2.4.0-5)
trixie: resolved (fix
debian
CVE-2014-8104MEDIUMCVSS 6.8fixed in openvpn 2.3.4-5 (bookworm)2014
CVE-2014-8104 [MEDIUM] CVE-2014-8104: openvpn - OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 all...
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
Scope: local
bookworm: resolved (fixed in 2.3.4-5)
bullseye: resolved (fixed in 2.3.4-5)
forky: resolved (fixed in 2.3.4-5)
sid: resolved (fixed in 2.3.4-5)
trixie: resolved (fi
debian
CVE-2013-2061LOWCVSS 2.6fixed in openvpn 2.3.1-1 (bookworm)2013
CVE-2013-2061 [LOW] CVE-2013-2061: openvpn - The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when runn...
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
Scope: local
bookworm: resolved (fixed in 2.3.1-1)
bullseye: resolved (fi
debian
CVE-2008-3459LOWCVSS 7.6fixed in openvpn 2.1~rc9-1 (bookworm)2008
CVE-2008-3459 [HIGH] CVE-2008-3459: openvpn - Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on...
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
Scope: local
bookworm: resolved (fixed in 2.1~rc9-1)
bullseye: resolved (fixed in 2.1~rc9-1)
forky: resolved
debian
CVE-2006-1629MEDIUMCVSS 9.0fixed in openvpn 2.0.6-1 (bookworm)2006
CVE-2006-1629 [CRITICAL] CVE-2006-1629: openvpn - OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary c...
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.
Scope: local
bookworm: resolved (fixed in 2.0.6-1)
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2005-2532HIGHCVSS 5.0fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2532 [MEDIUM] CVE-2005-2532: openvpn - OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a pack...
OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.
Scope: local
bookworm: resolved (fixed in 2.0.2-1)
bullseye: resolved (fixed in 2.0.2-1)
forky:
debian
CVE-2005-2531HIGHCVSS 5.0fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2531 [MEDIUM] CVE-2005-2531: openvpn - OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication,...
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentic
debian
CVE-2005-2534HIGHCVSS 2.6fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2534 [LOW] CVE-2005-2534: openvpn - Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allo...
Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.
Scope: local
bookworm: resolved (fixed in 2.0.2-1)
bullseye: resolved (fixed in 2.0.2-1)
forky: resolved (fixed in 2.0.2-1)
sid: resol
debian
CVE-2005-2533HIGHCVSS 2.1fixed in openvpn 2.0.2-1 (bookworm)2005
CVE-2005-2533 [LOW] CVE-2005-2533: openvpn - OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows r...
OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.
Scope: local
bookworm: resolved (fixed in 2.0.2-1)
bullseye: resolved (fixed in 2.0.2-1)
forky: resolved (fixed in 2.0.2-1)
sid: resolved (fixed
debian
CVE-2005-3393MEDIUMCVSS 7.5fixed in openvpn 2.0.5-1 (bookworm)2005
CVE-2005-3393 [HIGH] CVE-2005-3393: openvpn - Format string vulnerability in the foreign_option function in options.c for Open...
Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.
Scope: local
bookworm: resolved (fixed in 2.0.5-1)
bullseye: resolved (fixed in 2.0.5-1)
forky: resolved (fixed in 2.0.5-1)
sid: resolved (fixed in 2.0.5-1)
t
debian
CVE-2005-3409LOWCVSS 5.0fixed in openvpn 2.0.5-1 (bookworm)2005
CVE-2005-3409 [MEDIUM] CVE-2005-3409: openvpn - OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to c...
OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.
Scope: local
bookworm: resolved (fixed in 2.0.5-1)
bullseye: resolved (fixed in 2.0.5-1)
forky: resolved (fixed in 2.0.5
debian
← Previous2 / 2