Control channel: refuse control channel messages with nonprintable characters in them. (CVE-2024-5594) References: - https://bugs.mageia.org/show_bug.cgi?id=33336 . MGASA-2024-0255 - Updated openvpn packages fix security vulnerability Publication date: 04 Jul 2024 URL: https://advisories.mageia.org/MGASA-2024-0255.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-5594 Control channel: refuse control channel messages with nonprintable characters in them. (CVE-2024-5594) References: - https://bugs.mageia.org/show_bug.cgi?id=33336 - https://lists.fedoraproject.org/archives/list/
Update to upstream OpenVPN 2.6.11 CVE-2024-5594: control channel: refuse control channel messages with nonprintable characters in them CVE-2024-28882: only call schedule_exit() once (on a given peer). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b611e122fb 2024-06-27 02:02:42.638234 -------------------------------------------------------------------------------- Name : openvpn Product : Fedora 40 Version : 2.6.11 Release : 1.fc40 URL : / Summary : A full-featured TLS VPN solution Description : OpenVPN is a robust and highly flexible tunneling application that uses all of the encryption, authentication, and certification features of the OpenSSL library to securely tunnel IP networks over a single UDP or TCP port. It can use the Marcus Franz Xaver Johannes Oberhumers LZO library for compression. -------------------------------------------------------------------------------- Update Information: Update to upstream OpenVPN 2.6.11 CVE-2024-5594: control channel: refuse control channel messages with nonprintable characters in them CVE-2024-28882: only call schedule_exit() once (on a given peer) -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 21 2024 Frank Lichtenheld - 2.6.11-1 - Update to upstream OpenVPN 2.6.11 - Remove obsolete "beta release" qualifier from Summary -------------------------------------------------------------------------------- References: [ 1 ] Bug #2270512 - openvpn-2.6.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2270512 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b611e122fb' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.