Name
openvpn
Version
2.6.14
Type
library
Description
A full-featured SSL VPN solution via tun device.
Licenses
GPL-2.0-only
PURL
-
CPE
cpe:2.3:*:openvpn:openvpn:2.6.14:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
Fix memcmp check for the hmac verification in the 3way
Arne Schwabe <arne@rfc2549.org>
CVE-2025-13086
2
configure.ac: eliminate build path from openvpn --version
Yi Zhao <yi.zhao@windriver.com>
Vulnerabilities#
Name
Analysis
Description
False Positive
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
Patched
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
False Positive
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.