OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.
This Cyber News was published on www.tenable.com. Publication date: Mon, 06 Jan 2025 00:00:00 +0000