UBUNTU-CVE-2022-0547
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-0547
UBUNTU-CVE-2022-0547
Summary:
Details: OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
References: https://ubuntu.com/security/CVE-2022-0547, https://community.openvpn.net/openvpn/wiki/CVE-2022-0547, https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements, https://ubuntu.com/security/notices/USN-5347-1, https://www.cve.org/CVERecord?id=CVE-2022-0547, https://ubuntu.com/security/notices/USN-6850-1
Affected packages
Package
Name: openvpn
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
