Gert Doering reports that OpenVPN 2.6.11 fixes two security bugs (three on Windows):
CVE-2024-5594: control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load. (Reynir Björnsson)
CVE-2024-28882: only call schedule_exit() once (on a given peer). Security scope: an authenticated client can make the server "keep the session" even when the server has been told to disconnect this client. (Reynir Björnsson)
This Cyber News was published on www.tenable.com. Publication date: Sat, 22 Jun 2024 16:56:12 +0000