Commit 9d1cfe

2025-01-21 09:29:59 Samuli Seppänen: Add CVE-2024-28882 page
/dev/null .. security-announcements/cve-2024-28882.md
@@ 0,0 1,16 @@
+ # CVE-2024-28882
+
+ # Summary
+
+ OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session only call schedule_exit() once (on a given peer).
+
+ # Security scope
+
+ An authenticated client can make the server "keep the session" even when the server has been told to disconnect this client.
+
+ Affected versions: 2.6.0 until 2.6.10 (inclusive)
+
+ # References
+ * Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html
+ * CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28882
+ * Reported by: Reynir Björnsson
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9