CVE-2024-5594

Name
CVE-2024-5594
Description
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@openvpn.net https://community.openvpn.net/openvpn/wiki/CVE-2024-5594
security@openvpn.net https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/03/msg00005.html

Match rules

CPE URI Source package Min version Max version
openvpn >= 0 < 2.6.11
cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:* openvpn >= 2.6.0 < 2.6.11

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
openvpn edge-main 2.6.11-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openvpn edge-main 2.6.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.9-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.6.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.6-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.3-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.5.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn edge-main 2.4.9-r0 None possibly vulnerable
openvpn edge-main 2.4.6-r0 None possibly vulnerable
openvpn 3.22-main 2.6.11-r0 None fixed
openvpn 3.22-main 2.6.7-r0 None possibly vulnerable
openvpn 3.22-main 2.5.6-r0 None possibly vulnerable
openvpn 3.22-main 2.5.2-r0 None possibly vulnerable
openvpn 3.22-main 2.4.9-r0 None possibly vulnerable
openvpn 3.22-main 2.4.6-r0 None possibly vulnerable
openvpn 3.21-main 2.6.11-r0 None fixed
openvpn 3.21-main 2.6.7-r0 None possibly vulnerable
openvpn 3.21-main 2.5.6-r0 None possibly vulnerable
openvpn 3.21-main 2.5.2-r0 None possibly vulnerable
openvpn 3.21-main 2.4.9-r0 None possibly vulnerable
openvpn 3.21-main 2.4.6-r0 None possibly vulnerable
openvpn 3.20-main 2.6.11-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openvpn 3.20-main 2.6.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn 3.20-main 2.6.7-r0 None possibly vulnerable
openvpn 3.20-main 2.5.6-r0 None possibly vulnerable
openvpn 3.20-main 2.5.2-r0 None possibly vulnerable
openvpn 3.20-main 2.4.9-r0 None possibly vulnerable
openvpn 3.20-main 2.4.6-r0 None possibly vulnerable
openvpn 3.19-main 2.6.11-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openvpn 3.19-main 2.6.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openvpn 3.19-main 2.6.7-r0 None possibly vulnerable
openvpn 3.19-main 2.5.6-r0 None possibly vulnerable
openvpn 3.19-main 2.5.2-r0 None possibly vulnerable
openvpn 3.19-main 2.4.9-r0 None possibly vulnerable
openvpn 3.19-main 2.4.6-r0 None possibly vulnerable
openvpn 3.18-main 2.6.11-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openvpn 3.17-main 2.5.10-r1 Natanael Copa <ncopa@alpinelinux.org> fixed