[CLSA-2025:1744710425] Fix CVE(s): CVE-2024-5594
Type:
security
Severity:
Low
Release date:
2025-04-15 14:17:48 UTC
Description:
* SECURITY UPDATE: Improper PUSH_REPLY sanitization allows attackers to inject arbitrary data into third-party executables - debian/patches/CVE-2024-5594.patch: Properly handle null bytes and invalid characters in control - CVE-2024-5594 * UPDATE CERTIFICATES: Renew sample keys - debian/patches/sample-keys-renew.patch: Renew sample keys for 10 years
Updated packages:
  • openvpn_2.4.4-2ubuntu1.7+tuxcare.els1_amd64.deb
    sha:3d070fadde56d129af7241c34fd7a947dd51b5f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.