USN-6850-1: OpenVPN vulnerability
26 June 2024
OpenVPN could allow unintended access to network services.
Releases
Packages
- openvpn - virtual private network software
Details
It was discovered that OpenVPN incorrectly handled certain configurations
with multiple authentication plugins. A remote attacker could possibly use
this issue to bypass authentication using incomplete credentials.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
openvpn
-
2.3.10-1ubuntu2.2+esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
openvpn
-
2.3.2-7ubuntu3.2+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-5347-1: openvpn