ELA-601-1 openvpn security update

authentication bypass

2022-04-28
Packageopenvpn
Version2.3.4-5+deb8u3
Related CVEs CVE-2017-12166 CVE-2020-15078 CVE-2022-0547


Several issues were discovered in OpenVPN, a Virtual Private Network server and client, that could lead to authentication bypass when using deferred auth plugins.

Note that this upload disables support for multiple deferred auth plugins, following the upstream fix for CVE-2022-0547.



For Debian 8 jessie, these problems have been fixed in version 2.3.4-5+deb8u3.

We recommend that you upgrade your openvpn packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.