Debian 10225 Published by

An openvpn security update has been released for Debian GNU/Linux 8 Extended LTS to address several issues.



ELA-601-1 openvpn security update

Package openvpn
Version 2.3.4-5+deb8u3
Related CVEs CVE-2017-12166 CVE-2020-15078 CVE-2022-0547

Several issues were discovered in OpenVPN, a Virtual Private Network server and client, that could lead to authentication bypass when using deferred auth plugins.

Note that this upload disables support for multiple deferred auth plugins, following the upstream fix for CVE-2022-0547.

For Debian 8 jessie, these problems have been fixed in version 2.3.4-5+deb8u3.

We recommend that you upgrade your openvpn packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-601-1 openvpn security update