UbuntuUpdates.org

Package "openvpn"

Name: openvpn

Description:

virtual private network daemon

Latest version: 2.6.12-1ubuntu1.2
Release: oracular (24.10)
Level: security
Repository: main
Homepage: https://openvpn.net/

Links


Download "openvpn"


Other versions of "openvpn" in Oracular

Repository Area Version
base main 2.6.12-1ubuntu1
updates main 2.6.12-1ubuntu1.2

Changelog

Version: 2.6.12-1ubuntu1.2 2025-04-03 16:07:18 UTC

  openvpn (2.6.12-1ubuntu1.2) oracular-security; urgency=medium

  * SECURITY UPDATE: denial of service issue
    - debian/patches/CVE-2025-2704.patch: allow tls-crypt-v2 to be setup
      only on initial packet of a session in src/openvpn/ssl.c,
      src/openvpn/ssl_common.h, src/openvpn/ssl_pkt.c,
      src/openvpn/ssl_pkt.h, src/openvpn/tls_crypt.c,
      src/openvpn/tls_crypt.h, tests/unit_tests/openvpn/test_tls_crypt.c.
    - CVE-2025-2704

 -- Marc Deslauriers <email address hidden> Tue, 01 Apr 2025 12:05:41 -0400

CVE-2025-2704 OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and repla



About   -   Send Feedback to @ubuntu_updates