Commit df5e1e

2025-02-27 10:17:24 Samuli Seppänen: Switch to non-AI version
Security Announcements/CVE-2024-28882.md ..
@@ 1,12 1,12 @@
# CVE-2024-28882: OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
- OpenVPN should only call `schedule_exit()` once for a given peer.
+ only call schedule_exit() once (on a given peer).
- **Security scope:** An authenticated client can make the server "keep the session" even when the server has been told to disconnect this client.
+ Security scope: an authenticated client can make the server "keep the session" even when the server has been told to disconnect this client.
- **Affected versions:** 2.6.0 until 2.6.10 (inclusive)
+ Affected versions: 2.6.0 until 2.6.10 (inclusive)
- ## References
- - Release notes: [OpenVPN Mailing List](https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html)
- - CVE record: [CVE-2024-28882](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28882)
- - Reported by: Reynir Björnsson
\ No newline at end of file
+ ### References
+ * Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html
+ * CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28882
+ * Reported by: Reynir Björnsson
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9